Risk-Centric, Business-Aligned, and Built to Scale
The Process for Attack Simulation and Threat Analysis (PASTA) is a seven-stage threat modeling methodology that ties technical risk directly to business impact — co-authored by a member of Fork's team.
See PASTA run automatically on your own application
PASTA (Process for Attack Simulation and Threat Analysis) is a risk-centric threat modeling methodology co-authored by Tony UcedaVélez, founder and CEO of VerSprite, and security leader Marco M. Morana. Fork is a practical implementation of that same framework, built by the team that created it.
Unlike methodologies that work purely from a technical checklist, PASTA is evidence-based and attacker-focused — it simulates real-world attack scenarios and ties every finding back to business impact, likelihood, and inherent risk. That's what lets security and business stakeholders review the same threat model and agree on what actually matters.
Each stage builds on the last, moving from business context down to a quantified, prioritized risk picture.
Establish the business and compliance context for the application — what it does, who relies on it, and what's actually at stake if it's compromised.
Map the technologies, dependencies, and entry points that make up the application's exposure — the terrain an attacker would actually have to work with.
Break the application into its components and data flows, identifying trust boundaries where risk assumptions change.
Identify relevant threat actors and scenarios using threat intelligence, building the attack trees that later stages will test against.
Correlate the attack surface against known weaknesses and vulnerabilities, connecting design-level issues to concrete technical findings.
Simulate how identified threats would actually play out against the application, testing attack trees rather than relying on hypothetical severity ratings alone.
Quantify residual risk and business impact, producing a prioritized view that security and business stakeholders can act on together.
STRIDE, the most common alternative, categorizes threats into six technical types — spoofing, tampering, repudiation, information disclosure, denial of service, and elevation of privilege — typically applied per component. It's a strong entry point for structured technical review.
PASTA takes a different starting point: business objectives first, technical detail second. The two aren't mutually exclusive — some teams use STRIDE within individual PASTA stages — but PASTA is the better fit when the goal is a threat model that business stakeholders can actually engage with, not just a technical artifact for the security team.
For a full breakdown of how PASTA-based tools compare to other threat modeling platforms, see our Fork vs. the Field comparison.
Fork runs the full PASTA methodology on your own application, built by the team who wrote it.
30-minute conversation. No commitment required.