Attack Deck: Six STRIDE Suits, Defence Deck and Information Deck
Click on the back of the card to see the complete suit of cards.
Spoofing Suit
Attacks to procedures can maliciously impersonate users but can also spoof websites or servers. The cards can be used to create attacks based on (spear-)phishing, credential stealing, password brute-forcing, man-in-the-middle attacks, and abuse of admin configuration,
Tampering Suit
Attacks that alter data at rest, e.g. by exploiting a vulnerability in application front-ends or transit, e.g. due to a lack of message encryption,
Repudiation Suit
Threats to claim to have not performed an action. The cards allow the creation of attacks against logging functionality, the auditing process and insufficient user authentication,
Information Disclosure Suit
Threats to the confidentiality of information. The cards allow the creation of attacks exploiting inadequate encryption procedures for data at rest and in transit, flawed system configurations and non-adequate user security policies.
Denial of Service Suit
Availability of services to users. The cards allow the creation of attacks based on botnets, physical sabotage, system crash vulnerabilities, and social engineering.
Elevation of Privilege Suit
Threats against the authorisation controls. The cards allow the creation of a variety of code execution attacks, as well as abuse of physical security controls and social engineering attacks as baiting.
Defence Suit
Defence cards describe a pattern of behaviour that protects the player against an exploitation attempt.
Information Suit
Games master can use Scaffolding by framing, guiding and supporting using the information deck of cards.