OWASP Cornucopia: Open Source Threat Modeling supported by dotNET lab


In cybersecurity, threat modeling plays a crucial role in identifying and addressing risks in web applications. OWASP, the Open Worldwide Application Security Project, is a globally recognized non-profit organization committed to improving software security. One of its initiatives, OWASP Cornucopia, offers an accessible and playful way to model and discuss security risks in web applications.
What is OWASP Cornucopia?
OWASP Cornucopia is a card game that helps teams identify security risks in web applications. By using a playful but structured approach, it encourages teams to identify potentially vulnerable parts of their applications and discuss improvements. Developers score points in the game by bringing vulnerabilities to light themselves.
This helps them and security professionals proactively implement security measures before weaknesses can be exploited.

A Cornucopia reference website
Our teams of software developers enthusiastically got started with Cornucopia. However, we quickly noticed that some cards needed extra explanation to keep the game running smoothly. Unfortunately, you can only fit a limited number of words on a playing card. Luckily, Cornucopia is an open-source project, so we could tackle this ourselves. And that is exactly what we did.
We launched a reference website where we could show extra information for each card. We also described possible scenarios in which the card was relevant. A QR code on the new cards ensured that every card linked to its online version. In that way, we could also keep the information up to date.

Donation to the open-source community
The core team of the Cornucopia project was immediately enthusiastic about this approach. They not only saw its value, but were also convinced it could help a wider audience within the security community. It quickly became clear: to further strengthen Cornucopia, the reference website had to be available to everyone.
That is why we decided to officially donate the site to the open-source project. This was not only a step forward for Cornucopia's accessibility, but also a strengthening of the open-source ethos: working together, sharing knowledge and collectively improving software security.
This step coincided with the release of Cornucopia 2.1, an important update that brought new functionality and improvements. One of the most impactful additions was the expansion of security for mobile apps, making Cornucopia even better suited to the growing security challenges around app development. This makes it easier for developers and security professionals to identify and address threats when building apps.
After several technical refinements and optimizations, the website went live at cornucopia.owasp.org. From that moment, it became a central point for everyone who wants to use Cornucopia to make applications safer. We look forward to seeing how the community uses it and how the project continues to develop.


Webshop
In addition to the reference website, we also had the decks printed physically. We now distribute them through our webshop. Attentive readers can use discount code 'dotnetlab-blog' for a 35% discount on their order.
