Method
Threat modeling is treated as a repeatable practice: identify assets, define trust boundaries, map likely attack paths, and tie each path to preventive or detective controls.
Assets
User data, scan outputs, orchestration state, and service tokens.
Actors
Unauthenticated attackers, abusive users, and compromised service identities.
Controls
Access gating, verification workflows, and event-level observability.