What Is PASTA Threat Modeling?

Risk-Centric, Business-Aligned, and Built to Scale

The Process for Attack Simulation and Threat Analysis (PASTA) is a seven-stage threat modeling methodology that ties technical risk directly to business impact — co-authored by a member of Fork's team.

Talk to Our Team

See PASTA run automatically on your own application

A Methodology Built to Align Security With the Business

PASTA (Process for Attack Simulation and Threat Analysis) is a risk-centric threat modeling methodology co-authored by Tony UcedaVélez, founder and CEO of VerSprite, and security leader Marco M. Morana. Fork is a practical implementation of that same framework, built by the team that created it.

Unlike methodologies that work purely from a technical checklist, PASTA is evidence-based and attacker-focused — it simulates real-world attack scenarios and ties every finding back to business impact, likelihood, and inherent risk. That's what lets security and business stakeholders review the same threat model and agree on what actually matters.

The Seven Stages of PASTA

Each stage builds on the last, moving from business context down to a quantified, prioritized risk picture.

01

Define Objectives

Establish the business and compliance context for the application — what it does, who relies on it, and what's actually at stake if it's compromised.

02

Define Attack Surface

Map the technologies, dependencies, and entry points that make up the application's exposure — the terrain an attacker would actually have to work with.

03

Decompose Application

Break the application into its components and data flows, identifying trust boundaries where risk assumptions change.

04

Threat Analysis

Identify relevant threat actors and scenarios using threat intelligence, building the attack trees that later stages will test against.

05

Weakness and Vulnerability Analysis

Correlate the attack surface against known weaknesses and vulnerabilities, connecting design-level issues to concrete technical findings.

06

Attack Modeling and Simulation

Simulate how identified threats would actually play out against the application, testing attack trees rather than relying on hypothetical severity ratings alone.

07

Risk and Impact Analysis

Quantify residual risk and business impact, producing a prioritized view that security and business stakeholders can act on together.

Why Teams Choose PASTA

Risk-Centric Focus
Prioritizes threats based on business impact rather than just technical vulnerabilities.
Real-World Simulation
Emulates realistic attack scenarios to uncover potential weaknesses, not just theoretical ones.
Comprehensive Analysis
Merges technical and business perspectives for a well-rounded threat assessment.
Iterative Process
Allows continuous refinement and adaptation as threats evolve, rather than a one-time snapshot.

How PASTA Compares to Other Methodologies

STRIDE, the most common alternative, categorizes threats into six technical types — spoofing, tampering, repudiation, information disclosure, denial of service, and elevation of privilege — typically applied per component. It's a strong entry point for structured technical review.

PASTA takes a different starting point: business objectives first, technical detail second. The two aren't mutually exclusive — some teams use STRIDE within individual PASTA stages — but PASTA is the better fit when the goal is a threat model that business stakeholders can actually engage with, not just a technical artifact for the security team.

For a full breakdown of how PASTA-based tools compare to other threat modeling platforms, see our Fork vs. the Field comparison.

Frequently Asked Questions

What does PASTA stand for?
PASTA stands for Process for Attack Simulation and Threat Analysis. It's a risk-centric threat modeling methodology that runs through seven stages, from defining business objectives to a final risk and impact analysis.
Who created the PASTA methodology?
PASTA was co-authored by Tony UcedaVélez, founder and CEO of VerSprite, and security leader Marco M. Morana. Fork is built by the team behind the methodology itself.
How is PASTA different from STRIDE?
STRIDE categorizes threats into six technical types (spoofing, tampering, and so on) and is typically applied per component. PASTA is risk-centric and business-aligned: it ties technical threats back to business impact through a structured seven-stage process, rather than working from a fixed technical checklist alone.
Is PASTA suitable for small teams, or only large enterprises?
PASTA scales in both directions. Its structure works for a single application assessment or a full enterprise portfolio, which is part of why it's positioned as a risk-centric methodology rather than a one-size-fits-all checklist.
How long does a PASTA threat model take to build?
Done manually, a full PASTA exercise can take days per application. Fork automates the seven stages so a first threat model is typically ready in under two hours.

See PASTA Automated, Not Just Diagrammed

Fork runs the full PASTA methodology on your own application, built by the team who wrote it.

Contact Us

30-minute conversation. No commitment required.

Download the PASTA eBook