Back to insights
Cybersecurity 27 March 2025

OWASP Cornucopia: Open Source Threat Modeling supported by dotNET lab

Featured image for OWASP Cornucopia: Open Source Threat Modeling supported by dotNET lab

In cybersecurity, threat modeling plays a crucial role in identifying and addressing risks in web applications. OWASP, the Open Worldwide Application Security Project, is a globally recognized non-profit organization committed to improving software security. One of its initiatives, OWASP Cornucopia, offers an accessible and playful way to model and discuss security risks in web applications.

What is OWASP Cornucopia?

OWASP Cornucopia is a card game that helps teams identify security risks in web applications. By using a playful but structured approach, it encourages teams to identify potentially vulnerable parts of their applications and discuss improvements. Developers score points in the game by bringing vulnerabilities to light themselves.

This helps them and security professionals proactively implement security measures before weaknesses can be exploited.

Team playing OWASP Cornucopia with cards and reference website

A Cornucopia reference website

Our teams of software developers enthusiastically got started with Cornucopia. However, we quickly noticed that some cards needed extra explanation to keep the game running smoothly. Unfortunately, you can only fit a limited number of words on a playing card. Luckily, Cornucopia is an open-source project, so we could tackle this ourselves. And that is exactly what we did.

We launched a reference website where we could show extra information for each card. We also described possible scenarios in which the card was relevant. A QR code on the new cards ensured that every card linked to its online version. In that way, we could also keep the information up to date.

Cornucopia reference website built by dotNET lab

Donation to the open-source community

The core team of the Cornucopia project was immediately enthusiastic about this approach. They not only saw its value, but were also convinced it could help a wider audience within the security community. It quickly became clear: to further strengthen Cornucopia, the reference website had to be available to everyone.

That is why we decided to officially donate the site to the open-source project. This was not only a step forward for Cornucopia's accessibility, but also a strengthening of the open-source ethos: working together, sharing knowledge and collectively improving software security.

This step coincided with the release of Cornucopia 2.1, an important update that brought new functionality and improvements. One of the most impactful additions was the expansion of security for mobile apps, making Cornucopia even better suited to the growing security challenges around app development. This makes it easier for developers and security professionals to identify and address threats when building apps.

After several technical refinements and optimizations, the website went live at cornucopia.owasp.org. From that moment, it became a central point for everyone who wants to use Cornucopia to make applications safer. We look forward to seeing how the community uses it and how the project continues to develop.

Homepage of the OWASP Cornucopia reference website
Detail page of an OWASP Cornucopia card on the reference website

Webshop

In addition to the reference website, we also had the decks printed physically. We now distribute them through our webshop. Attentive readers can use discount code 'dotnetlab-blog' for a 35% discount on their order.

Ready to try it yourself?

Interested in working with Cornucopia? Or do you want to know more about how threat modeling can help your organization?

Contact our security specialist