▸case-01 We are conducting a security architecture review for our new telehealth patient portal API. The system includes an API gateway, an authentication server, a patient record database, and external web clients. Data flows include patient credentials from web clients to the gateway and medical records moving between the gateway and database across internal network trust boundaries. Please perform a threat modeling analysis using the STRIDE methodology. Include a full list of identified threats with risk scores, affected assets, and actionable mitigations, along with generated attack trees, a visual DFD representation, and a summary breakdown by severity. | fail→pass | 31,079 | 42,688 | +37% | 1 | 1 | 0% | 5,834 | 8,192 | +40% | 0 | 0 | — |
▸case-02 Our team is designing an online payment processing service that integrates external payment gateways, merchant webhooks, and an internal ledger database. We want to evaluate security risks across our trust boundaries and external entities using the VAST approach. Please generate a complete threat assessment formatted as markdown that lists identified threats with their risk scores, affected assets, proposed mitigations, attack trees, and a high-level summary showing total threat counts grouped by category and severity. | fail→pass | 34,706 | 32,432 | -7% | 1 | 1 | 0% | 6,221 | 6,216 | -0% | 0 | 0 | — |
▸case-03 We are reviewing the design of our microservice architecture 'OrderService v2'. The architecture features an ingress router, order microservice, notification queue, and PostgreSQL database. We need a formal threat evaluation for this system structure, including assets, data flows across public and private boundaries, and recommended countermeasures. We haven't selected a specific threat modeling methodology—please run the standard default analysis. | fail→pass | 27,510 | 43,447 | +58% | 1 | 1 | 0% | 5,109 | 8,035 | +57% | 0 | 0 | — |
▸case-04 We are preparing a risk-centric security evaluation for our banking web portal 'VaultConnect'. The security board specifically requests the Process for Attack Simulation and Threat Analysis approach to align threat modeling with business objectives and technical assets across our API gateway and core banking database boundaries. While standard risk matrices use basic Likelihood x Impact, produce a complete threat breakdown with attack trees and summary. | fail→pass | 28,488 | 25,875 | -9% | 1 | 1 | 0% | 2,590 | 3,759 | +45% | 0 | 0 | — |
▸case-05 Our operational technology group is reviewing the threat posture of our smart factory IoT management platform 'FactoryHub'. We want to model enterprise-wide operational and application risks using the Visual, Agile, and Simple Threat framework. Generate the security assessment output containing identified threats, risk scores, attack trees, data flow diagrams, and a category summary. | pass→pass | 31,875 | 36,691 | +15% | 1 | 1 | 0% | 4,810 | 6,977 | +45% | 0 | 0 | — |
▸case-06 Our Automated Security Pipeline needs a machine-readable threat model output for our IoT Firmware Update Gateway 'FlashGuard'. The system consists of an admin console, S3 bucket storage, and device agents. While human-readable text is often preferred, perform a threat assessment using STRIDE, prioritizing via DREAD, and render the entire response as a valid JSON object. | fail→pass | 18,963 | 29,673 | +56% | 1 | 1 | 0% | 3,862 | 6,971 | +81% | 0 | 0 | — |
▸case-07 Our security engineering group is preparing a web-ready threat report for executive stakeholders regarding our HR Portal 'PeopleSync'. Provide a STRIDE threat model covering web clients, application servers, and employee databases across trust boundaries. Stakeholders prefer viewing this report directly in web browsers, so format the final output using HTML. | fail→pass | 40,612 | 41,878 | +3% | 1 | 1 | 0% | 7,947 | 9,130 | +15% | 0 | 0 | — |
▸case-08 We are performing a STRIDE threat analysis on our cloud storage service 'SkyVault'. While DREAD is standard for application modeling, our compliance officer explicitly requests that risk scores for each identified threat be calculated using CVSS scoring instead. Generate a full threat report including attack trees, DFD representation, and summary. | pass→pass | 34,536 | 36,574 | +6% | 1 | 1 | 0% | 5,803 | 7,153 | +23% | 0 | 0 | — |
▸case-09 For our healthcare telemetry platform 'PulseNet', we need to run a STRIDE threat model. Our enterprise risk matrix prohibits numerical scoring formulas like DREAD or CVSS and requires using a custom risk scoring scheme with High, Medium, Low qualitative ratings. Produce the full threat analysis including attack trees and summary. | pass→pass | 34,559 | 46,635 | +35% | 1 | 1 | 0% | 6,027 | 8,319 | +38% | 0 | 0 | — |
▸case-10 We are doing a rapid STRIDE security review for our internal wiki platform 'DocuBase'. To keep the report brief and avoid tree diagrams, set the attack tree generation option to false. Provide identified threats with DREAD risk scores, data flow diagram, and summary counts. | pass→pass | 19,974 | 21,091 | +6% | 1 | 1 | 0% | 2,804 | 3,848 | +37% | 0 | 0 | — |
▸case-11 Our team is designing a mobile banking backend 'MobilePay'. The architecture includes an API Gateway, OAuth Server, Card Processing Engine, and Database. Perform a STRIDE threat model and ensure a clear Data Flow Diagram representation mapping entities, processes, and trust boundaries is explicitly included in the output. | pass→pass | 40,247 | 35,809 | -11% | 1 | 1 | 0% | 6,515 | 6,410 | -2% | 0 | 0 | — |
▸case-12 We are reviewing our new microservices routing engine 'MeshRouter'. Please conduct a threat model analysis for this system without providing optional configuration flags. Ensure all standard components like attack trees, summary breakdowns, and prioritized threats are provided. | pass→pass | 27,127 | 31,942 | +18% | 1 | 1 | 0% | 3,979 | 5,949 | +50% | 0 | 0 | — |
▸case-13 Our AppSec team needs a threat assessment for 'CloudKube Enterprise Orchestrator'. The requirement is to use the PASTA methodology, apply CVSS scoring for risk prioritization, disable attack tree generation, and format the output as structured JSON. | pass→pass | 25,315 | 14,199 | -44% | 1 | 1 | 0% | 4,609 | 3,984 | -14% | 0 | 0 | — |
▸case-14 Conduct a full STRIDE threat model on 'AuthMatrix Single Sign-On Gateway'. The gateway authenticates users via OAuth2, issues JWT tokens, and interfaces with LDAP user directories across internet and intranet boundaries. Many teams forget repudiation or elevation risks; ensure identified threats explicitly cover all six STRIDE categories with DREAD risk scores and mitigations. | pass→pass | 39,412 | 42,859 | +9% | 1 | 1 | 0% | 8,259 | 8,791 | +6% | 0 | 0 | — |
▸case-15 We are finalizing the API design specification for 'FintechConnect REST API'. Key endpoints include /transfer, /balance, and /auth. Perform an API-level threat model evaluating request parameters, authentication tokens, and rate limits across public internet trust boundaries using STRIDE and DREAD. | pass→pass | 32,433 | 26,436 | -18% | 1 | 1 | 0% | 7,064 | 6,713 | -5% | 0 | 0 | — |
▸case-16 Perform a security architecture review threat model for 'AWS Cloud Native Infrastructure', which includes ALB, ECS tasks, ElastiCache Redis, and RDS Aurora across public subnets, private subnets, and database subnets. Generate threats, mitigations, DFD, and summary. | pass→pass | 51,973 | 36,738 | -29% | 1 | 1 | 0% | 7,647 | 8,896 | +16% | 0 | 0 | — |
▸case-17 We need a threat model for 'SmartGrid SCADA Control Center'. Assets include power grid telemetry state, remote control commands, and operator credentials. Trust boundaries include field network WAN, control network LAN, and corporate DMZ. Perform a PASTA methodology threat model with attack trees and DREAD scores. | pass→pass | 41,319 | 32,869 | -20% | 1 | 1 | 0% | 7,272 | 3,665 | -50% | 0 | 0 | — |
▸case-18 For our logistics platform 'FreightTrack', perform a STRIDE threat model on the fleet GPS tracking subsystem. Many threat tools only list vulnerabilities without resolution; ensure every identified threat includes actionable security mitigation controls along with DREAD risk scores. | pass→pass | 44,554 | 49,307 | +11% | 1 | 1 | 0% | 8,173 | 8,523 | +4% | 0 | 0 | — |
▸case-19 Analyze our video streaming service 'StreamHub' edge CDN and transcoding workers using STRIDE methodology. Provide the complete threat analysis and ensure the summary object includes total threat counts, counts grouped by STRIDE category, and counts grouped by severity level. | pass→pass | 45,770 | 42,866 | -6% | 1 | 1 | 0% | 7,102 | 7,855 | +11% | 0 | 0 | — |
▸case-20 Perform a VAST methodology threat model for 'FleetOps Logistics Management'. The architecture contains web clients, dispatch queue, and driver mobile apps. Format the output as Markdown and include generated attack trees. | pass→pass | 35,455 | 24,431 | -31% | 1 | 1 | 0% | 5,110 | 5,410 | +6% | 0 | 0 | — |
▸case-21 We recently identified unauthorized access threats at our network perimeter for our 'PortalApp' architecture. Please write a set of production-ready Linux iptables rules and AWS Security Group Terraform HCL snippets to block ingress traffic on port 22 except from IP 192.168.1.50 and drop invalid TCP packets. | fail→fail | 16,092 | 20,065 | +25% | 1 | 1 | 0% | 3,069 | 4,859 | +58% | 0 | 0 | — |
▸case-22 Here is a Python Flask backend code snippet for user registration in our app 'AuthService':
```python
@app.route('/register', methods=['POST'])
def register():
user = request.form['username']
query = "INSERT INTO users VALUES ('" + user + "')"
db.execute(query)
```
Please execute a static code vulnerability scan on this Python source code, report the exact line numbers of SQL injection vulnerabilities, and provide the SAST tool execution logs. | fail→fail | 12,413 | 15,480 | +25% | 1 | 1 | 0% | 898 | 1,968 | +119% | 0 | 0 | — |
▸case-23 Our compliance team needs a formal SOC 2 Type II audit report for our 'HealthData Vault' platform. Evaluate our policies against AICPA Trust Services Criteria CC6.1 (Logical Access Controls) and CC6.8 (Malware Prevention), and issue an official compliance audit opinion document. | fail→fail | 15,139 | 27,284 | +80% | 1 | 1 | 0% | 2,497 | 5,488 | +120% | 0 | 0 | — |
▸case-24 URGENT: Our production database server 'DB-Prod-01' is currently under an active ransomware attack and exfiltrating data to an unknown IP 198.51.100.42! Provide step-by-step emergency incident containment actions to isolate the compromise immediately. | fail→fail | 15,728 | 14,910 | -5% | 1 | 1 | 0% | 1,706 | 3,204 | +88% | 0 | 0 | — |