Average Ratings 0 Ratings
Average Ratings 0 Ratings
Description
From various assets and countermeasures to factoids, personas, and architectural components, you can enter or upload a diverse array of data related to security, usability, and requirements to uncover valuable insights, including the links between requirements and risks as well as the rationale behind persona traits. Since no single perspective can encompass the complexity of a system, you can effortlessly create 12 distinct views of your developing design that examine aspects such as people, risks, requirements, architecture, and even geographical location. Additionally, as your preliminary design progresses, you can automatically produce threat models like Data Flow Diagrams (DFDs). Utilize open-source intelligence regarding potential threats and viable security architectures to assess your attack surface effectively. Furthermore, you can visualize all the security, usability, and design factors related to the risks associated with your product and how they interact with one another. This comprehensive approach ensures a thorough understanding of your system's vulnerabilities and strengths.
Description
Fork is a SaaS platform designed for threat modeling that enables both security and product teams to conduct ongoing, risk-oriented assessments of applications by utilizing the established PASTA (Process for Attack Simulation and Threat Analysis) framework. This allows teams to swiftly identify the most probable and significant risks in less than two hours while ensuring that security measures are aligned with business objectives. By merging specialized threat libraries with current vulnerability information and threat intelligence, Fork accurately quantifies residual risks and aids in conducting business impact analyses. The platform also implements quality controls throughout the threat modeling process to enhance overall effectiveness. Additionally, Fork features a consolidated security insights dashboard that links threats directly to the attack surface of your application, while incorporating recognized frameworks and taxonomies like MITRE, OWASP, CWE, CVE (with EPSS), CAPEC, ATT&CK, D3FEND, and ASVS, which facilitates focused mitigation strategies and practical outcomes. This comprehensive approach not only enhances security posture but also fosters collaboration between technical and business teams.
API Access
Has API
No
API Access
Has API
Yes
Integrations
Checkmarx
No
GitLab
No
OpenAI
No
OpenCTI
No
ServiceNow
No
Tavily
No
Veracode
No
Integrations
Checkmarx
Yes
GitLab
Yes
OpenAI
Yes
OpenCTI
Yes
ServiceNow
Yes
Tavily
Yes
Veracode
Yes
Pricing Details
Free
Free Trial
No
Free Version
Yes
Pricing Details
$75,000/yr
Starting at $75,000/year
Up to $150,000/year for 500–2,000 threat models
Up to $150,000/year for 500–2,000 threat models
Free Trial
No
Free Version
Yes
Deployment
Web-Based
Yes
On-Premises
No
iPhone App
No
iPad App
No
Android App
No
Windows
No
Mac
No
Linux
No
Chromebook
No
Deployment
Web-Based
Yes
On-Premises
No
iPhone App
No
iPad App
No
Android App
No
Windows
No
Mac
No
Linux
No
Chromebook
No
Customer Support
Business Hours
No
Live Rep (24/7)
No
Online Support
Yes
Customer Support
Business Hours
No
Live Rep (24/7)
No
Online Support
Yes
Types of Training
Training Docs
Yes
Webinars
No
Live Training (Online)
No
In Person
No
Types of Training
Training Docs
Yes
Webinars
No
Live Training (Online)
No
In Person
No
Vendor Details
Company Name
CAIRIS
Website
cairis.org
Vendor Details
Company Name
VerSprite Cybersecurity
Founded
2007
Country
United States
Website
forktm.com
Product Features
Requirements Management
Automated Functional Sizing
No
Automated Requirements QA
No
Automated Test Generation
No
Automated Use Case Modeling
No
Change Management
No
Collaboration
No
History Tracking
No
Prioritization
No
Reporting
No
Status Reporting
No
Status Tracking
No
Summary Reports
No
Task Management
No
To-Do List
No
Traceability
No
User Defined Attributes
No