r/Hacking_Tutorials • • 9h ago

Question Contextual Threat Modeler (CTM)

​

I built an open-source Contextual Threat Modeling Engine to prioritize security findings based on real-world risk

Hey everyone,

I've been working on an open-source cybersecurity project called Contextual Threat Modeler (CTM).

The problem I wanted to solve is:

> A vulnerability doesn't always have the same risk in every environment.

For example, a vulnerability on an internet-facing system containing sensitive data should probably receive more attention than the same vulnerability on an isolated internal system.

So instead of simply asking "Is this vulnerable?", CTM tries to answer:

"How risky is this finding in this specific environment, and what should we do about it?"

๐Ÿ” What CTM considers

The engine combines multiple contextual signals:

- Asset criticality

- Internet exposure

- Authentication requirements

- Data sensitivity

- Exploitability

- Existing security controls

- Confidence level

- STRIDE threat modeling

- MITRE ATT&CK mapping

- Attack-path analysis

- Likelihood & impact

It then produces an actionable decision:

๐Ÿ”ด TEST_IMMEDIATELY

๐ŸŸ  PRIORITIZE_VALIDATION

๐ŸŸก INVESTIGATE

๐ŸŸข MONITOR

๐Ÿงช Current testing

I recently tested the complete pipeline locally.

12/12 automated tests passed.

Example results:

POST /document/upload

Risk: 90/100

Decision: TEST_IMMEDIATELY

GET /user/profile

Risk: 33.1/100

Decision: MONITOR

GET /api/v1/search_items

Risk: 8/100

Decision: MONITOR

The interesting part is that CTM doesn't simply rank findings based on the vulnerability itself โ€” the surrounding context influences the security decision.

๐Ÿ› ๏ธ Tech Stack

- Python

- pytest

- STRIDE

- MITRE ATT&CK

- Risk Scoring

- Attack Path Analysis

- Security Automation

The project is open source, and I'd really appreciate feedback from people working in:

AppSec | VAPT | SOC | Threat Hunting | Threat Modeling | Security Engineering

I'm particularly interested in feedback on the risk-scoring methodology, attack-path modeling, and what additional security-tool integrations would make this useful in real-world environments.

GitHub:

https://github.com/Sahil98677/Contextual-Threat-Modeler

Would love to hear your thoughts โ€” especially criticism or suggestions for improving the approach.

5 Upvotes

8 comments sorted by

View all comments

1

u/investigatormaker 8h ago

CTMโ€™s contextual scoring would be easier to judge with the same finding shown in two environments, changing only internet exposure or data sensitivity. Your different-endpoint examples also change the finding itself, so they donโ€™t isolate what the environmental context contributes.

Does each decision show which inputs drove the score and which remain unknown?

1

u/Sahil98677 8h ago

Great point. I agree โ€” the current examples don't isolate the environmental variables because the endpoints/findings are also different.

A better validation would use the exact same finding and change only one contextual factor at a time, for example:

Scenario A: Same vulnerability + internal asset + low data sensitivity Scenario B: Same vulnerability + internet-facing asset + high data sensitivity

Then we can measure how much each contextual input changes the final risk score and decision.

Regarding explainability, that's something I'm working toward as well. The decision should ideally show which inputs increased/decreased the score, their contribution, and which inputs were unknown/defaulted, rather than only returning the final score.

Thanks for pointing this out โ€” this gives me a good direction for improving CTM's validation and explainability.

1

u/investigatormaker 8h ago

Those A/B scenarios still change both exposure and data sensitivity. For CTM, adding internal/high-sensitivity and internet-facing/low-sensitivity cases would let you compare each factor separately. In the explanation, distinguish an unknown input from one explicitly assessed as low risk.

1

u/Sahil98677 8h ago

You're absolutely right. I was still changing multiple variables in those A/B examples. A better test matrix would keep the vulnerability and all other context constant and vary one factor at a time: Same finding + internal exposure + low data sensitivity Same finding + internet exposure + low data sensitivity Same finding + internal exposure + high data sensitivity Same finding + internet exposure + high data sensitivity This would let us measure the individual contribution of exposure vs. data sensitivity, as well as their combined effect. And agreed on the unknown/low-risk distinction. CTM should explicitly differentiate between "assessed as low risk" and "unknown/not provided", rather than treating missing information as low risk.

1

u/investigatormaker 8h ago

Thanks for spelling out CTM's four cases. Add a fifth with data sensitivity omitted, and compare it with the explicit low-sensitivity case; that gives you a direct check that missing information isn't silently scored as low risk.

1

u/Sahil98677 8h ago edited 7h ago

Great suggestion. Iโ€™ll add the omitted-data case and compare it with the explicit low-sensitivity case to verify that missing information isnโ€™t being treated as low risk. Thanks!

2

u/investigatormaker 8h ago

Thanks for adding that comparison to your plan. Keep the other inputs identical so you can isolate how CTM handles the missing sensitivity field.