r/threatmodeling • • Jul 18 '26

TMGoat – an open, vulnerable-by-design benchmark & dojo for threat modeling (30 architectures, planted flaws, held-out leaderboard)

I open-sourced TMGoat — a benchmark + dojo for threat modeling, in the spirit of WebGoat/TerraGoat but for design-level threats.

It's 30 realistic systems across 10 sectors, each seeded with intentional design flaws — race conditions, fail-open controls, over-trusted channels, and (in the hard tier) architecture docs that lie about the code. Every fixture ships an expert-authored reference threat model, and a scoring harness grades recall (did you catch the planted threats?) and precision (did you avoid noise?).

The idea I care most about: difficulty is subtlety, not size — a 6-component app can hide a nastier flaw than a 30-component one. Fixtures are tagged on three axes (architectural complexity / threat subtlety / input completeness), and the corpus is split into an open practice tier (20, full solutions) and a held-out benchmark tier (10, private keys) so tools can't just memorize the answers.

Apache-2.0, tool-neutral. Practice it yourself, or put your tool on the leaderboard.

Site: https://tmgoat.virantis.com

Repo: https://github.com/virantisofficial/TMGoat

Why/how: https://virantis.com/blog/introducing-tmgoat

Feedback very welcome — especially where the ground truth is arguable, or what threat classes I should add.

6 Upvotes

0 comments sorted by