Riskio Card Decks

Attack Deck: Six STRIDE Suits, Defence Deck and Information Deck

Click on the back of the card to see the complete suit of cards.

Spoofing Suit

Attacks to procedures can maliciously impersonate users but can also spoof websites or servers. The cards can be used to create attacks based on (spear-)phishing, credential stealing, password brute-forcing, man-in-the-middle attacks, and abuse of admin configuration,

Tampering Suit

Attacks that alter data at rest, e.g. by exploiting a vulnerability in application front-ends or transit, e.g. due to a lack of message encryption,

Repudiation Suit

Threats to claim to have not performed an action. The cards allow the creation of attacks against logging functionality, the auditing process and insufficient user authentication,

Information Disclosure Suit

Threats to the confidentiality of information. The cards allow the creation of attacks exploiting inadequate encryption procedures for data at rest and in transit, flawed system configurations and non-adequate user security policies.

Denial of Service Suit

Availability of services to users. The cards allow the creation of attacks based on botnets, physical sabotage, system crash vulnerabilities, and social engineering.

Elevation of Privilege Suit

Threats against the authorisation controls. The cards allow the creation of a variety of code execution attacks, as well as abuse of physical security controls and social engineering attacks as baiting.

Defence Suit

Defence cards describe a pattern of behaviour that protects the player against an exploitation attempt.

Information Suit

Games master can use Scaffolding by framing, guiding and supporting using the information deck of cards.