security product · CCSK v5 + SCS-C03

Threat modeling for cloud — from developer to security contributor

You already know how the system works — that is the whole advantage. This path turns that into a repeatable habit: read a business use case and a dev team's architecture, find what can go wrong, decide what to do about it, and check the work — the same four questions every time, on real AWS, Azure and private-cloud designs.

50 lessons · M0–M7 Threat Model Studio 8 graded cases CCSK v5 · 12 domains SCS-C03 · 6 domains free, no login

The spine: four questions, every time

Every module, lesson, case and interview answer in this product hangs on the same four questions (Shostack). Answer them in order and nothing important gets skipped.

1 · What are we working on?Actors, assets, data flows, trust boundaries.
2 · What can go wrong?STRIDE per element, attacker paths, threat statements.
3 · What do we do about it?Controls mapped to real AWS/Azure/K8s settings.
4 · Did we do a good job?Coverage checks, peer review, a living model.
Beat 1 of 4 auto-advancing · 15s a beat

1 · What are we working on?

A phone app sends an order — item, address, and the price the app computed — to an API, which writes it to a database.

The lesson route

M0 is open now. M1–M7, the Studio, the labs, the cases and the mocks ship next, each as its own card — see the full roadmap and your progress →

📍 The lesson routeM0–M7, one page per lesson, with a progress ladder. 📝 QuizDomain-tagged questions, self-graded.bank ships with M1 — CS2 🧪 BenchBrowser labs, graded cases and portfolio projects.Studio ships next — CS1

Already shipped: the Expert-level deep dives

Before this product existed, the AI/ML roadmap's security phase built eight explainers at Expert depth. They stay exactly where they are — this path links to them rather than rebuilding them.