Process for Attack Simulation and Threat Analysis (PASTA)


Process for Attack Simulation and Threat Analysis (PASTA) is a seven-stage framework for threat modeling.

  • focuses on how attackers view infrastructure and applications

Stages

  1. Define business objectives
  2. Define the technical scope of assets and components
  3. Factor applications and identify application controls
  4. Perform threat analysis based on threat intelligence
  5. Vulnerability detection
  6. Analyze and model attacks
  7. Perform risk and impact analysis and develop countermeasures