Open, Community-Maintained, Free to Use
Fork's threat libraries map industry- and technology-specific threats to CWEs, CAPECs, CVEs, MITRE ATT&CK patterns, and OWASP ASVS controls. They're open source, MIT-licensed, and built with the community.
Open source and MIT-licensed on GitHub
Each threat library is structured as a hierarchical tree rather than a flat list, mapping threats, motives, and targets to the security standards and frameworks that matter for real assessments: CWEs (Common Weakness Enumeration), CAPECs (Common Attack Pattern Enumeration and Classification), CVEs (Common Vulnerabilities and Exposures), MITRE ATT&CK post-exploitation patterns and their mitigations, and OWASP ASVS controls.
That structure is what lets a threat surfaced in a PASTA-based model trace directly back to the standards your security and compliance teams already work from, instead of existing as an isolated finding.
Fifteen industry libraries are available today, each maintained as its own file and open to community contribution. Every library maps its industry's threat landscape back to CWEs, CAPECs, CVEs, MITRE ATT&CK patterns, and OWASP ASVS controls.
These libraries aren't a substitute for a formal compliance assessment, but they give teams a starting point for the application-layer risks a compliance program needs to account for. That's most direct in industries under regulatory scrutiny — payment card data in the Fintech & Credit Cards library sits close to PCI DSS scope, protected health information in the Healthcare library overlaps with HIPAA concerns, and the kind of structured, evidence-based risk analysis Fork produces is the same category of work that underpins a SOC 2 readiness effort.
Alongside industry libraries, Fork maintains libraries built around specific technologies rather than verticals. This category is newer and actively growing — it currently includes an AI threat library, added in the last few months, with more technology areas planned.
Every library lives as a JSON file in the Fork Community repository on GitHub, released under the MIT license. Anyone can propose changes through a pull request; contributions that pass peer review are folded into Fork's threat modeling platform with each new release, so the libraries powering your threat models stay current as the community adds to them.
These libraries feed directly into Fork's PASTA-based threat modeling workflow. Read more about the platform's features, or see how Fork compares to other threat modeling tools.
Explore the JSON files, open an issue, or submit a pull request — the repository is open to everyone.
MIT-licensed. Free to use, fork, and contribute to.