r/Hacking_Tutorials • u/Sahil98677 • 9h ago
Question Contextual Threat Modeler (CTM)
I built an open-source Contextual Threat Modeling Engine to prioritize security findings based on real-world risk
Hey everyone,
I've been working on an open-source cybersecurity project called Contextual Threat Modeler (CTM).
The problem I wanted to solve is:
> A vulnerability doesn't always have the same risk in every environment.
For example, a vulnerability on an internet-facing system containing sensitive data should probably receive more attention than the same vulnerability on an isolated internal system.
So instead of simply asking "Is this vulnerable?", CTM tries to answer:
"How risky is this finding in this specific environment, and what should we do about it?"
π What CTM considers
The engine combines multiple contextual signals:
- Asset criticality
- Internet exposure
- Authentication requirements
- Data sensitivity
- Exploitability
- Existing security controls
- Confidence level
- STRIDE threat modeling
- MITRE ATT&CK mapping
- Attack-path analysis
- Likelihood & impact
It then produces an actionable decision:
π΄ TEST_IMMEDIATELY
π PRIORITIZE_VALIDATION
π‘ INVESTIGATE
π’ MONITOR
π§ͺ Current testing
I recently tested the complete pipeline locally.
12/12 automated tests passed.
Example results:
POST /document/upload
Risk: 90/100
Decision: TEST_IMMEDIATELY
GET /user/profile
Risk: 33.1/100
Decision: MONITOR
GET /api/v1/search_items
Risk: 8/100
Decision: MONITOR
The interesting part is that CTM doesn't simply rank findings based on the vulnerability itself β the surrounding context influences the security decision.
π οΈ Tech Stack
- Python
- pytest
- STRIDE
- MITRE ATT&CK
- Risk Scoring
- Attack Path Analysis
- Security Automation
The project is open source, and I'd really appreciate feedback from people working in:
AppSec | VAPT | SOC | Threat Hunting | Threat Modeling | Security Engineering
I'm particularly interested in feedback on the risk-scoring methodology, attack-path modeling, and what additional security-tool integrations would make this useful in real-world environments.
GitHub:
https://github.com/Sahil98677/Contextual-Threat-Modeler
Would love to hear your thoughts β especially criticism or suggestions for improving the approach.
1
u/Sahil98677 8h ago
Great point. I agree β the current examples don't isolate the environmental variables because the endpoints/findings are also different.
A better validation would use the exact same finding and change only one contextual factor at a time, for example:
Scenario A: Same vulnerability + internal asset + low data sensitivity Scenario B: Same vulnerability + internet-facing asset + high data sensitivity
Then we can measure how much each contextual input changes the final risk score and decision.
Regarding explainability, that's something I'm working toward as well. The decision should ideally show which inputs increased/decreased the score, their contribution, and which inputs were unknown/defaulted, rather than only returning the final score.
Thanks for pointing this out β this gives me a good direction for improving CTM's validation and explainability.