Average Ratings 0 Ratings

Total
ease
features
design
support

No User Reviews. Be the first to provide a review:

Write a Review

Average Ratings 0 Ratings

Total
ease
features
design
support

No User Reviews. Be the first to provide a review:

Write a Review

Description

IriusRisk is an open Threat Modeling platform that can be used by any development and operations team – even those without prior security training. Whether your organization follows a framework or not, we can work with all the threat modeling methodologies, such as STRIDE, TRIKE, OCTAVE and PASTA. We support organisations in financial services, insurance, industrial automation, healthcare, private sector and more. IriusRisk is the industry's leading threat modeling and secure design solution in Application Security. With enterprise clients including Fortune 500 banks, payments, and technology providers, it empowers security and development teams to ensure applications have security built-in from the start - using its powerful threat modeling platform. Whether teams are implementing threat modeling from scratch, or scaling-up their existing operations, the IriusRisk approach results in improved speed-to-market, collaboration across security and development teams, and the avoidance of costly security flaws.

Description

MITRE ATT&CK® serves as a comprehensive, publicly-accessible repository detailing the tactics and techniques employed by adversaries, grounded in actual observations from the field. This repository acts as a crucial resource for shaping targeted threat models and strategies across various sectors, including private enterprises, government agencies, and the broader cybersecurity industry. By establishing ATT&CK, MITRE is advancing its commitment to creating a safer world through collaborative efforts aimed at enhancing cybersecurity efficacy. The ATT&CK framework is freely available to individuals and organizations alike, making it an invaluable tool for improving security practices. Adversaries often engage in active reconnaissance scans to collect pertinent information that aids in their targeting efforts, utilizing direct network traffic to probe victim infrastructure rather than employing indirect methods. This proactive approach to gathering intelligence underscores the importance of vigilance in cybersecurity to counter such tactics effectively.

API Access

Has API Yes 

API Access

Has API No 

Screenshots View All

Screenshots View All

Integrations

AWS CloudFormation Yes 
Amazon Web Services (AWS) Yes 
Azure DevOps Yes 
CucumberStudio Yes 
Datto EDR No 
Filigran No 
GitHub Yes 
Group-IB Threat Intelligence No 
JUnit Yes 
Jira Yes 
Jira Service Management Yes 
Microsoft Threat Modeling Tool Yes 
Microsoft Visio Yes 
OAuth Yes 
OWASP ZAP Yes 
Redmine Yes 
Serenity BDD Yes 
Sprocket Security No 
Terraform Yes 
ThreadFix Yes 

Integrations

AWS CloudFormation No 
Amazon Web Services (AWS) No 
Azure DevOps No 
CucumberStudio No 
Datto EDR Yes 
Filigran Yes 
GitHub No 
Group-IB Threat Intelligence Yes 
JUnit No 
Jira No 
Jira Service Management No 
Microsoft Threat Modeling Tool No 
Microsoft Visio No 
OAuth No 
OWASP ZAP No 
Redmine No 
Serenity BDD No 
Sprocket Security Yes 
Terraform No 
ThreadFix No 

Pricing Details

Enterprise licences can vary depending on integrations and threat modeling requirements. Please do contact us for a more detailed breakdown. Pricing is done by threat model and not by user to keep costs manageable and predictable.
Free Trial No 
Free Version Yes 

Pricing Details

No price information available.
Free Trial No 
Free Version No 

Deployment

Web-Based Yes 
On-Premises Yes 
iPhone App No 
iPad App No 
Android App No 
Windows No 
Mac No 
Linux No 
Chromebook No 

Deployment

Web-Based Yes 
On-Premises No 
iPhone App No 
iPad App No 
Android App No 
Windows No 
Mac No 
Linux No 
Chromebook No 

Customer Support

Business Hours Yes 
Live Rep (24/7) Yes 
Online Support Yes 

Customer Support

Business Hours No 
Live Rep (24/7) No 
Online Support Yes 

Types of Training

Training Docs Yes 
Webinars Yes 
Live Training (Online) Yes 
In Person Yes 

Types of Training

Training Docs Yes 
Webinars No 
Live Training (Online) No 
In Person No 

Vendor Details

Company Name

IriusRisk

Country

Spain

Website

www.iriusrisk.com/

Vendor Details

Company Name

MITRE ATT&CK

Country

United States

Website

attack.mitre.org

Product Features

Risk Management

Alerts/Notifications Yes 
Auditing Yes 
Business Process Control Yes 
Compliance Management Yes 
Corrective Actions (CAPA) Yes 
Dashboard Yes 
Exceptions Management Yes 
IT Risk Management Yes 
Internal Controls Management Yes 
Legal Risk Management No 
Mobile Access No 
Operational Risk Management Yes 
Predictive Analytics Yes 
Reputation Risk Management No 
Response Management No 
Risk Assessment Yes 

Alternatives

Devici Reviews

Devici

Security Compass

Alternatives

SD Elements Reviews

SD Elements

Security Compass
Fork Reviews

Fork

VerSprite Cybersecurity
DarkIQ Reviews

DarkIQ

Searchlight Cyber