/perspective/learn/threat-modeler/

Learning path

The threat modeler — You are securing a multi-agent system and want the attack surface, the defenses, and a worked example — in that order.

You are securing a multi-agent system and want the attack surface, the defenses, and a worked example — in that order.

For
The threat modeler
You will leave with
You will leave able to name the five attack surfaces, map each to the defense that guards it, and walk one threat from entry to mitigation.
Time
6 steps · ~30 min

Path position

The threat modeler: You are securing a multi-agent system and want the attack surface, the defenses, and a worked example — in that order.

This is inferred from the page and path structure. Nothing is saved as completion state.

Overview

Before step 1 of 6

You will leave able to name the five attack surfaces, map each to the defense that guards it, and walk one threat from entry to mitigation.

6 steps · ~30 min

Begin path

The attack surface

A MAS multiplies every entry and exit point of a single LLM call. The security landing indexes 27 threats under five attack surfaces — the map you navigate by.

You should be able to name the five attack surfaces and one threat that lives on each.

Start step 1

Steps

  1. The attack surface

    A MAS multiplies every entry and exit point of a single LLM call. The security landing indexes 27 threats under five attack surfaces — the map you navigate by.

    You should be able to name the five attack surfaces and one threat that lives on each.

  2. One threat, end to end

    Prompt injection (LLM01) is the canonical case: crafted input overrides instructions, directly or through content the model reads. Read one threat in full before generalizing.

    You should be able to distinguish direct, indirect, and multimodal injection, and name a mitigation for each.

  3. The architectural lens

    MAESTRO files each threat onto one of its seven layers — foundation model, data operations, agent frameworks, deployment & infrastructure, evaluation & observability, security & compliance, and the agent ecosystem — so you can reason about exposure per layer.

    You should be able to pick one layer and name a threat that targets it plus one cross-layer risk.

  4. Where the defenses live

    The catalog's mitigations are not new patterns — they are the Governance & Safety subdomain of L4: HITL gates, sandboxes, output validation, least privilege, audit trail.

    You should be able to map three threats to the governance pattern that guards each.

  5. Which threats apply to you

    Not every system faces every threat. Five yes/no questions about autonomy, memory, tools, multi-agent structure, and humans accumulate the threats your specific design carries.

    You should be able to answer the five questions for your system and list the threats that survive.

  6. A worked threat model

    The RPA expense-reimbursement case study walks a real agent through the MAESTRO layers with concrete findings and mitigations — the capstone that ties surface, lens, and defense together.

    You should be able to trace one baseline threat through the case study from its entry point to its mitigation.

Search

Search patterns, frameworks, and pages.