Custom Report Template Reference
Generated for app version: 1.15.0
Root Variables
| Variable | Description |
|---|---|
| assetGroups | Asset group summary entries including generated image and display fields |
| assets | All assets in the project |
| assumptions | All project assumptions |
| attackScenarios | Applicable attack scenarios |
| attackScenariosAll | All attack scenarios including not applicable entries |
| attackScenariosNotApplicable | Attack scenarios marked as not applicable |
| characterizationScope | Characterization scope analysis fields |
| checklists | Checklist groups enriched with module, current level and generated requirements table |
| config | The configuration root object |
| contextDiagrams | All context diagrams |
| countermeasures | Applicable countermeasures |
| countermeasuresAll | All countermeasures including not applicable entries |
| countermeasuresNotApplicable | Countermeasures marked as not applicable |
| dataFlowDiagrams | All data flow diagrams |
| diagrams | All diagrams in the project |
| document | Document metadata like date, app version and logo |
| hardwareDiagrams | All hardware diagrams |
| mitigationProcesses | All mitigation processes |
| objectivesImpact | Object impact analysis fields |
| processDiagrams | Process model stacks exported as diagram-like entries |
| project | The project root object |
| softwareDiagrams | Software model stacks exported as diagram-like entries |
| systemThreats | All system threats |
| testCases | All test cases |
| threatSources | All threat sources |
| useCaseDiagrams | All use case diagrams |
Root Variable Details
assetGroups
- Description: Asset group summary entries including generated image and display fields
| Name | Kind | Description |
|---|---|---|
| Name | scalar | Name of the asset group |
| Image | scalar | Rendered overview image (HTML img tag) for the asset group |
| assets | list |
Assets contained in the group as exported Asset entries |
assets
- Description: All assets in the project
| Name | Kind | Description |
|---|---|---|
| Description | scalar | Description text of the entry |
| Hyperlinks | scalar | Referenced hyperlinks of the entry |
| Identifier | scalar | Unique reference identifier of the entry |
| ImpactCats | scalar | Impact categories assigned to the asset |
| ImpactPerProtectionGoal | scalar | Impact values grouped by protection goal |
| LongName | scalar | Full display name including prefix, number, and name. |
| Name | scalar | Display name of the entry |
| Number | scalar | Number shown for the entry |
| Sensitivity | scalar | Sensitivity level for data assets |
| Type | scalar | User-facing type label of the entry (for example Asset or Data) |
assumptions
- Description: All project assumptions
| Name | Kind | Description |
|---|---|---|
| AssumptionCategories | scalar | Assigned categories for the assumption |
| Automations | scalar | Configured risk metric automation values |
| Categories | scalar | Assigned categories for the assumption |
| Definitions | scalar | Configured risk metric automation values |
| Description | scalar | Description text of the entry |
| Hyperlinks | scalar | Referenced hyperlinks of the entry |
| Identifier | scalar | Unique reference identifier of the entry |
| LongName | scalar | Full display name including prefix, number, and name. |
| Name | scalar | Display name of the entry |
| Number | scalar | Number shown for the entry |
| Responsible | scalar | Responsible person or role |
| Validated | scalar | Validation state of the assumption |
attackScenarios
- Description: Applicable attack scenarios
| Name | Kind | Description |
|---|---|---|
| AffectedAssetObjects | scalar | Affected assets and objects linked to the entry |
| AttackVector | scalar | Attack vector classification |
| CAPECID | scalar | CAPEC identifier of the linked attack vector |
| CAPECLink | scalar | CAPEC Link |
| Countermeasures | scalar | Countermeasures linked to the entry |
| CvssNotes31 | scalar | CVSS/OWASP risk value, vector, score, or note |
| CvssNotes40 | scalar | CVSS/OWASP risk value, vector, score, or note |
| CvssScore31 | scalar | CVSS/OWASP risk value, vector, score, or note |
| CvssScore40 | scalar | CVSS/OWASP risk value, vector, score, or note |
| CvssVector31 | scalar | CVSS/OWASP risk value, vector, score, or note |
| CvssVector40 | scalar | CVSS/OWASP risk value, vector, score, or note |
| CWEID | scalar | CWE identifier of the linked attack vector |
| CWELink | scalar | CWE Link |
| Description | scalar | Description text of the entry |
| Diagram | scalar | Diagram context of the entry |
| EMB3DID | scalar | EMB3D identifier of the linked attack vector |
| EMB3DLink | scalar | EMB3 D Link |
| Hyperlinks | scalar | Referenced hyperlinks of the entry |
| Identifier | scalar | Unique reference identifier of the entry |
| LinkedRequirements | scalar | Requirements linked to the entry |
| LinkedScenarios | scalar | Attack scenarios linked to the entry |
| LinkedTestCases | scalar | Test cases linked to the entry |
| LongName | scalar | Full display name including prefix, number, and name. |
| MyTags | scalar | Tags assigned to the entry |
| Name | scalar | Display name of the entry |
| Number | scalar | Number shown for the entry |
| OwaspScore | scalar | CVSS/OWASP risk value, vector, score, or note |
| OwaspVector | scalar | CVSS/OWASP risk value, vector, score, or note |
| ProtectionGoals | scalar | Protection goals affected by the scenario |
| RemainingCvssNotes31 | scalar | CVSS/OWASP risk value, vector, score, or note |
| RemainingCvssNotes40 | scalar | CVSS/OWASP risk value, vector, score, or note |
| RemainingCvssScore31 | scalar | CVSS/OWASP risk value, vector, score, or note |
| RemainingCvssScore40 | scalar | CVSS/OWASP risk value, vector, score, or note |
| RemainingCvssVector31 | scalar | CVSS/OWASP risk value, vector, score, or note |
| RemainingCvssVector40 | scalar | CVSS/OWASP risk value, vector, score, or note |
| RemainingOwaspScore | scalar | CVSS/OWASP risk value, vector, score, or note |
| RemainingOwaspVector | scalar | CVSS/OWASP risk value, vector, score, or note |
| RiskStrategy | scalar | Selected risk strategy |
| RiskStrategyReason | scalar | Reasoning and notes for the selected risk strategy |
| RNotesCVSS | scalar | CVSS/OWASP risk value, vector, score, or note |
| RNotesCVSS40 | scalar | CVSS/OWASP risk value, vector, score, or note |
| RNotesCVSSdefault | scalar | CVSS/OWASP risk value, vector, score, or note |
| RRNotesCVSS | scalar | CVSS/OWASP risk value, vector, score, or note |
| RRNotesCVSS40 | scalar | CVSS/OWASP risk value, vector, score, or note |
| RRNotesCVSSdefault | scalar | CVSS/OWASP risk value, vector, score, or note |
| RRScoreCVSS | scalar | CVSS/OWASP risk value, vector, score, or note |
| RRScoreCVSS40 | scalar | CVSS/OWASP risk value, vector, score, or note |
| RRScoreCVSSdefault | scalar | CVSS/OWASP risk value, vector, score, or note |
| RRScoreOwaspRR | scalar | CVSS/OWASP risk value, vector, score, or note |
| RRVectorCVSS | scalar | CVSS/OWASP risk value, vector, score, or note |
| RRVectorCVSS40 | scalar | CVSS/OWASP risk value, vector, score, or note |
| RRVectorCVSSdefault | scalar | CVSS/OWASP risk value, vector, score, or note |
| RRVectorOwaspRR | scalar | CVSS/OWASP risk value, vector, score, or note |
| RScoreCVSS | scalar | CVSS/OWASP risk value, vector, score, or note |
| RScoreCVSS40 | scalar | CVSS/OWASP risk value, vector, score, or note |
| RScoreCVSSdefault | scalar | CVSS/OWASP risk value, vector, score, or note |
| RScoreOwaspRR | scalar | CVSS/OWASP risk value, vector, score, or note |
| RVectorCVSS | scalar | CVSS/OWASP risk value, vector, score, or note |
| RVectorCVSS40 | scalar | CVSS/OWASP risk value, vector, score, or note |
| RVectorCVSSdefault | scalar | CVSS/OWASP risk value, vector, score, or note |
| RVectorOwaspRR | scalar | CVSS/OWASP risk value, vector, score, or note |
| Status | scalar | Status |
| SystemThreats | scalar | System threats linked to the scenario |
| Target | scalar | Primary target object of the scenario |
| Targets | scalar | All target objects linked to the scenario |
| TargetType | scalar | Type of the selected target object |
| ThreatCategories | scalar | Threat categories for grouping and classifying threats |
| ThreatSources | scalar | Threat sources linked to the scenario |
| ThreatState | scalar | Status regarding the applicability of the scenario |
| TreatmentState | scalar | Threatment status (Passed, Not passed, Not yet completed) |
| TreatmentStatus | scalar | Threatment status (Passed, Not passed, Not yet completed) |
attackScenariosAll
- Description: All attack scenarios including not applicable entries
| Name | Kind | Description |
|---|---|---|
| AffectedAssetObjects | scalar | Affected assets and objects linked to the entry |
| AttackVector | scalar | Attack vector classification |
| CAPECID | scalar | CAPEC identifier of the linked attack vector |
| CAPECLink | scalar | CAPEC Link |
| Countermeasures | scalar | Countermeasures linked to the entry |
| CvssNotes31 | scalar | CVSS/OWASP risk value, vector, score, or note |
| CvssNotes40 | scalar | CVSS/OWASP risk value, vector, score, or note |
| CvssScore31 | scalar | CVSS/OWASP risk value, vector, score, or note |
| CvssScore40 | scalar | CVSS/OWASP risk value, vector, score, or note |
| CvssVector31 | scalar | CVSS/OWASP risk value, vector, score, or note |
| CvssVector40 | scalar | CVSS/OWASP risk value, vector, score, or note |
| CWEID | scalar | CWE identifier of the linked attack vector |
| CWELink | scalar | CWE Link |
| Description | scalar | Description text of the entry |
| Diagram | scalar | Diagram context of the entry |
| EMB3DID | scalar | EMB3D identifier of the linked attack vector |
| EMB3DLink | scalar | EMB3 D Link |
| Hyperlinks | scalar | Referenced hyperlinks of the entry |
| Identifier | scalar | Unique reference identifier of the entry |
| LinkedRequirements | scalar | Requirements linked to the entry |
| LinkedScenarios | scalar | Attack scenarios linked to the entry |
| LinkedTestCases | scalar | Test cases linked to the entry |
| LongName | scalar | Full display name including prefix, number, and name. |
| MyTags | scalar | Tags assigned to the entry |
| Name | scalar | Display name of the entry |
| Number | scalar | Number shown for the entry |
| OwaspScore | scalar | CVSS/OWASP risk value, vector, score, or note |
| OwaspVector | scalar | CVSS/OWASP risk value, vector, score, or note |
| ProtectionGoals | scalar | Protection goals affected by the scenario |
| RemainingCvssNotes31 | scalar | CVSS/OWASP risk value, vector, score, or note |
| RemainingCvssNotes40 | scalar | CVSS/OWASP risk value, vector, score, or note |
| RemainingCvssScore31 | scalar | CVSS/OWASP risk value, vector, score, or note |
| RemainingCvssScore40 | scalar | CVSS/OWASP risk value, vector, score, or note |
| RemainingCvssVector31 | scalar | CVSS/OWASP risk value, vector, score, or note |
| RemainingCvssVector40 | scalar | CVSS/OWASP risk value, vector, score, or note |
| RemainingOwaspScore | scalar | CVSS/OWASP risk value, vector, score, or note |
| RemainingOwaspVector | scalar | CVSS/OWASP risk value, vector, score, or note |
| RiskStrategy | scalar | Selected risk strategy |
| RiskStrategyReason | scalar | Reasoning and notes for the selected risk strategy |
| RNotesCVSS | scalar | CVSS/OWASP risk value, vector, score, or note |
| RNotesCVSS40 | scalar | CVSS/OWASP risk value, vector, score, or note |
| RNotesCVSSdefault | scalar | CVSS/OWASP risk value, vector, score, or note |
| RRNotesCVSS | scalar | CVSS/OWASP risk value, vector, score, or note |
| RRNotesCVSS40 | scalar | CVSS/OWASP risk value, vector, score, or note |
| RRNotesCVSSdefault | scalar | CVSS/OWASP risk value, vector, score, or note |
| RRScoreCVSS | scalar | CVSS/OWASP risk value, vector, score, or note |
| RRScoreCVSS40 | scalar | CVSS/OWASP risk value, vector, score, or note |
| RRScoreCVSSdefault | scalar | CVSS/OWASP risk value, vector, score, or note |
| RRScoreOwaspRR | scalar | CVSS/OWASP risk value, vector, score, or note |
| RRVectorCVSS | scalar | CVSS/OWASP risk value, vector, score, or note |
| RRVectorCVSS40 | scalar | CVSS/OWASP risk value, vector, score, or note |
| RRVectorCVSSdefault | scalar | CVSS/OWASP risk value, vector, score, or note |
| RRVectorOwaspRR | scalar | CVSS/OWASP risk value, vector, score, or note |
| RScoreCVSS | scalar | CVSS/OWASP risk value, vector, score, or note |
| RScoreCVSS40 | scalar | CVSS/OWASP risk value, vector, score, or note |
| RScoreCVSSdefault | scalar | CVSS/OWASP risk value, vector, score, or note |
| RScoreOwaspRR | scalar | CVSS/OWASP risk value, vector, score, or note |
| RVectorCVSS | scalar | CVSS/OWASP risk value, vector, score, or note |
| RVectorCVSS40 | scalar | CVSS/OWASP risk value, vector, score, or note |
| RVectorCVSSdefault | scalar | CVSS/OWASP risk value, vector, score, or note |
| RVectorOwaspRR | scalar | CVSS/OWASP risk value, vector, score, or note |
| Status | scalar | Status |
| SystemThreats | scalar | System threats linked to the scenario |
| Target | scalar | Primary target object of the scenario |
| Targets | scalar | All target objects linked to the scenario |
| TargetType | scalar | Type of the selected target object |
| ThreatCategories | scalar | Threat categories for grouping and classifying threats |
| ThreatSources | scalar | Threat sources linked to the scenario |
| ThreatState | scalar | Status regarding the applicability of the scenario |
| TreatmentState | scalar | Threatment status (Passed, Not passed, Not yet completed) |
| TreatmentStatus | scalar | Threatment status (Passed, Not passed, Not yet completed) |
attackScenariosNotApplicable
- Description: Attack scenarios marked as not applicable
| Name | Kind | Description |
|---|---|---|
| AffectedAssetObjects | scalar | Affected assets and objects linked to the entry |
| AttackVector | scalar | Attack vector classification |
| CAPECID | scalar | CAPEC identifier of the linked attack vector |
| CAPECLink | scalar | CAPEC Link |
| Countermeasures | scalar | Countermeasures linked to the entry |
| CvssNotes31 | scalar | CVSS/OWASP risk value, vector, score, or note |
| CvssNotes40 | scalar | CVSS/OWASP risk value, vector, score, or note |
| CvssScore31 | scalar | CVSS/OWASP risk value, vector, score, or note |
| CvssScore40 | scalar | CVSS/OWASP risk value, vector, score, or note |
| CvssVector31 | scalar | CVSS/OWASP risk value, vector, score, or note |
| CvssVector40 | scalar | CVSS/OWASP risk value, vector, score, or note |
| CWEID | scalar | CWE identifier of the linked attack vector |
| CWELink | scalar | CWE Link |
| Description | scalar | Description text of the entry |
| Diagram | scalar | Diagram context of the entry |
| EMB3DID | scalar | EMB3D identifier of the linked attack vector |
| EMB3DLink | scalar | EMB3 D Link |
| Hyperlinks | scalar | Referenced hyperlinks of the entry |
| Identifier | scalar | Unique reference identifier of the entry |
| LinkedRequirements | scalar | Requirements linked to the entry |
| LinkedScenarios | scalar | Attack scenarios linked to the entry |
| LinkedTestCases | scalar | Test cases linked to the entry |
| LongName | scalar | Full display name including prefix, number, and name. |
| MyTags | scalar | Tags assigned to the entry |
| Name | scalar | Display name of the entry |
| Number | scalar | Number shown for the entry |
| OwaspScore | scalar | CVSS/OWASP risk value, vector, score, or note |
| OwaspVector | scalar | CVSS/OWASP risk value, vector, score, or note |
| ProtectionGoals | scalar | Protection goals affected by the scenario |
| RemainingCvssNotes31 | scalar | CVSS/OWASP risk value, vector, score, or note |
| RemainingCvssNotes40 | scalar | CVSS/OWASP risk value, vector, score, or note |
| RemainingCvssScore31 | scalar | CVSS/OWASP risk value, vector, score, or note |
| RemainingCvssScore40 | scalar | CVSS/OWASP risk value, vector, score, or note |
| RemainingCvssVector31 | scalar | CVSS/OWASP risk value, vector, score, or note |
| RemainingCvssVector40 | scalar | CVSS/OWASP risk value, vector, score, or note |
| RemainingOwaspScore | scalar | CVSS/OWASP risk value, vector, score, or note |
| RemainingOwaspVector | scalar | CVSS/OWASP risk value, vector, score, or note |
| RiskStrategy | scalar | Selected risk strategy |
| RiskStrategyReason | scalar | Reasoning and notes for the selected risk strategy |
| RNotesCVSS | scalar | CVSS/OWASP risk value, vector, score, or note |
| RNotesCVSS40 | scalar | CVSS/OWASP risk value, vector, score, or note |
| RNotesCVSSdefault | scalar | CVSS/OWASP risk value, vector, score, or note |
| RRNotesCVSS | scalar | CVSS/OWASP risk value, vector, score, or note |
| RRNotesCVSS40 | scalar | CVSS/OWASP risk value, vector, score, or note |
| RRNotesCVSSdefault | scalar | CVSS/OWASP risk value, vector, score, or note |
| RRScoreCVSS | scalar | CVSS/OWASP risk value, vector, score, or note |
| RRScoreCVSS40 | scalar | CVSS/OWASP risk value, vector, score, or note |
| RRScoreCVSSdefault | scalar | CVSS/OWASP risk value, vector, score, or note |
| RRScoreOwaspRR | scalar | CVSS/OWASP risk value, vector, score, or note |
| RRVectorCVSS | scalar | CVSS/OWASP risk value, vector, score, or note |
| RRVectorCVSS40 | scalar | CVSS/OWASP risk value, vector, score, or note |
| RRVectorCVSSdefault | scalar | CVSS/OWASP risk value, vector, score, or note |
| RRVectorOwaspRR | scalar | CVSS/OWASP risk value, vector, score, or note |
| RScoreCVSS | scalar | CVSS/OWASP risk value, vector, score, or note |
| RScoreCVSS40 | scalar | CVSS/OWASP risk value, vector, score, or note |
| RScoreCVSSdefault | scalar | CVSS/OWASP risk value, vector, score, or note |
| RScoreOwaspRR | scalar | CVSS/OWASP risk value, vector, score, or note |
| RVectorCVSS | scalar | CVSS/OWASP risk value, vector, score, or note |
| RVectorCVSS40 | scalar | CVSS/OWASP risk value, vector, score, or note |
| RVectorCVSSdefault | scalar | CVSS/OWASP risk value, vector, score, or note |
| RVectorOwaspRR | scalar | CVSS/OWASP risk value, vector, score, or note |
| Status | scalar | Status |
| SystemThreats | scalar | System threats linked to the scenario |
| Target | scalar | Primary target object of the scenario |
| Targets | scalar | All target objects linked to the scenario |
| TargetType | scalar | Type of the selected target object |
| ThreatCategories | scalar | Threat categories for grouping and classifying threats |
| ThreatSources | scalar | Threat sources linked to the scenario |
| ThreatState | scalar | Status regarding the applicability of the scenario |
| TreatmentState | scalar | Threatment status (Passed, Not passed, Not yet completed) |
| TreatmentStatus | scalar | Threatment status (Passed, Not passed, Not yet completed) |
characterizationScope
- Description: Characterization scope analysis fields
| Name | Kind | Description |
|---|---|---|
checklists
- Description: Checklist groups enriched with module, current level and generated requirements table
| Name | Kind | Description |
|---|---|---|
| ModuleName | scalar | Module Name |
| Name | scalar | Display name of the entry |
| Description | scalar | Description text of the entry |
| TestReports | scalar | Test reports description or links |
| CurrentLevel | scalar | Current Level |
| SummaryTable | scalar | Summary Table |
| RequirementsTable | scalar | Requirements Table |
| requirements | list |
Requirements |
config
- Description: The configuration root object
| Name | Kind | Description |
|---|---|---|
| RiskAcceptanceCriteria | scalar | Configured risk acceptance criteria text of the default risk method |
| RiskAcceptanceLevel | scalar | Configured risk acceptance level name of the default risk method |
contextDiagrams
- Description: All context diagrams
| Name | Kind | Description |
|---|---|---|
| attackScenarios | list | Attack Scenarios |
| AttackScenarios | list | List of related attack scenarios |
| countermeasures | list | Countermeasures |
| Countermeasures | list | List of related countermeasures |
| Description | scalar | Description text of the entry |
| DiagramType | scalar | Type of the diagram entry |
| Hyperlinks | scalar | Referenced hyperlinks of the entry |
| Image | scalar | Rendered image payload of the diagram |
| Name | scalar | Display name of the entry |
| Path | scalar | Source path or location label of the diagram |
countermeasures
- Description: Applicable countermeasures
| Name | Kind | Description |
|---|---|---|
| AttackScenarios | list | List of related attack scenarios |
| AttackVectors | scalar | Attack vectors covered by the countermeasure |
| Control | scalar | Mapped control entry |
| Description | scalar | Description text of the entry |
| Diagram | scalar | Diagram context of the entry |
| EMB3DIDs | scalar | Linked EMB3D mitigation identifiers from the mapped control |
| Hyperlinks | scalar | Referenced hyperlinks of the entry |
| Identifier | scalar | Unique reference identifier of the entry |
| LinkedRequirements | scalar | Requirements linked to the countermeasure |
| LinkedTestCases | scalar | Test cases linked to the countermeasure |
| LongName | scalar | Full display name including prefix, number, and name. |
| MaxRisk | scalar | Maximum risk across linked attack scenarios |
| MitigationProcess | scalar | Assigned mitigation process |
| MitigationState | scalar | Status regarding applicability of the countermeasure |
| MyTags | scalar | Tags assigned to the entry |
| Name | scalar | Display name of the entry |
| Number | scalar | Number shown for the entry |
| Status | scalar | Status regarding applicability of the countermeasure |
| Targets | scalar | All target objects linked to the countermeasure |
countermeasuresAll
- Description: All countermeasures including not applicable entries
| Name | Kind | Description |
|---|---|---|
| AttackScenarios | list | List of related attack scenarios |
| AttackVectors | scalar | Attack vectors covered by the countermeasure |
| Control | scalar | Mapped control entry |
| Description | scalar | Description text of the entry |
| Diagram | scalar | Diagram context of the entry |
| EMB3DIDs | scalar | Linked EMB3D mitigation identifiers from the mapped control |
| Hyperlinks | scalar | Referenced hyperlinks of the entry |
| Identifier | scalar | Unique reference identifier of the entry |
| LinkedRequirements | scalar | Requirements linked to the countermeasure |
| LinkedTestCases | scalar | Test cases linked to the countermeasure |
| LongName | scalar | Full display name including prefix, number, and name. |
| MaxRisk | scalar | Maximum risk across linked attack scenarios |
| MitigationProcess | scalar | Assigned mitigation process |
| MitigationState | scalar | Status regarding applicability of the countermeasure |
| MyTags | scalar | Tags assigned to the entry |
| Name | scalar | Display name of the entry |
| Number | scalar | Number shown for the entry |
| Status | scalar | Status regarding applicability of the countermeasure |
| Targets | scalar | All target objects linked to the countermeasure |
countermeasuresNotApplicable
- Description: Countermeasures marked as not applicable
| Name | Kind | Description |
|---|---|---|
| AttackScenarios | list | List of related attack scenarios |
| AttackVectors | scalar | Attack vectors covered by the countermeasure |
| Control | scalar | Mapped control entry |
| Description | scalar | Description text of the entry |
| Diagram | scalar | Diagram context of the entry |
| EMB3DIDs | scalar | Linked EMB3D mitigation identifiers from the mapped control |
| Hyperlinks | scalar | Referenced hyperlinks of the entry |
| Identifier | scalar | Unique reference identifier of the entry |
| LinkedRequirements | scalar | Requirements linked to the countermeasure |
| LinkedTestCases | scalar | Test cases linked to the countermeasure |
| LongName | scalar | Full display name including prefix, number, and name. |
| MaxRisk | scalar | Maximum risk across linked attack scenarios |
| MitigationProcess | scalar | Assigned mitigation process |
| MitigationState | scalar | Status regarding applicability of the countermeasure |
| MyTags | scalar | Tags assigned to the entry |
| Name | scalar | Display name of the entry |
| Number | scalar | Number shown for the entry |
| Status | scalar | Status regarding applicability of the countermeasure |
| Targets | scalar | All target objects linked to the countermeasure |
dataFlowDiagrams
- Description: All data flow diagrams
| Name | Kind | Description |
|---|---|---|
| attackScenarios | list | Attack Scenarios |
| AttackScenarios | list | List of related attack scenarios |
| countermeasures | list | Countermeasures |
| Countermeasures | list | List of related countermeasures |
| Description | scalar | Description text of the entry |
| DiagramType | scalar | Type of the diagram entry |
| Hyperlinks | scalar | Referenced hyperlinks of the entry |
| Image | scalar | Rendered image payload of the diagram |
| Name | scalar | Display name of the entry |
| Path | scalar | Source path or location label of the diagram |
diagrams
- Description: All diagrams in the project
| Name | Kind | Description |
|---|---|---|
| attackScenarios | list | Attack Scenarios |
| AttackScenarios | list | List of related attack scenarios |
| countermeasures | list | Countermeasures |
| Countermeasures | list | List of related countermeasures |
| Description | scalar | Description text of the entry |
| DiagramType | scalar | Type of the diagram entry |
| Hyperlinks | scalar | Referenced hyperlinks of the entry |
| Image | scalar | Rendered image payload of the diagram |
| Name | scalar | Display name of the entry |
| Path | scalar | Source path or location label of the diagram |
document
- Description: Document metadata like date, app version and logo
| Name | Kind | Description |
|---|---|---|
| Date | scalar | Date of today |
| TableOfContents | scalar | Inserts the table of contents |
| TTModelerLogo | scalar | Image TTModeler logo |
| TTModelerVersion | scalar | Currently used TTModeler version |
hardwareDiagrams
- Description: All hardware diagrams
| Name | Kind | Description |
|---|---|---|
| attackScenarios | list | Attack Scenarios |
| AttackScenarios | list | List of related attack scenarios |
| countermeasures | list | Countermeasures |
| Countermeasures | list | List of related countermeasures |
| Description | scalar | Description text of the entry |
| DiagramType | scalar | Type of the diagram entry |
| Hyperlinks | scalar | Referenced hyperlinks of the entry |
| Image | scalar | Rendered image payload of the diagram |
| Name | scalar | Display name of the entry |
| Path | scalar | Source path or location label of the diagram |
mitigationProcesses
- Description: All mitigation processes
| Name | Kind | Description |
|---|---|---|
| AttackScenarios | scalar | Related attack scenarios |
| Countermeasures | scalar | Related countermeasures |
| Description | scalar | Description text of the entry |
| Hyperlinks | scalar | Referenced hyperlinks of the entry |
| Identifier | scalar | Unique reference identifier of the entry |
| LongName | scalar | Full display name including prefix, number, and name. |
| MaxRisk | scalar | Maximum risk of related attack scenarios |
| MitigationProcessState | scalar | Mitigation Process State |
| Name | scalar | Display name of the entry |
| Notes | list | Notes of the entry |
| Number | scalar | Number shown for the entry |
| Progress | scalar | Progress information of the process |
| Status | scalar | Status of the entry |
| Tasks | list | Task list of the process |
objectivesImpact
- Description: Object impact analysis fields
| Name | Kind | Description |
|---|---|---|
processDiagrams
- Description: Process model stacks exported as diagram-like entries
| Name | Kind | Description |
|---|---|---|
| attackScenarios | list | Attack Scenarios |
| AttackScenarios | list | List of related attack scenarios |
| countermeasures | list | Countermeasures |
| Countermeasures | list | List of related countermeasures |
| Description | scalar | Description text of the entry |
| DiagramType | scalar | Type of the diagram entry |
| Hyperlinks | scalar | Referenced hyperlinks of the entry |
| Image | scalar | Rendered image payload of the diagram |
| Name | scalar | Display name of the entry |
| Path | scalar | Source path or location label of the diagram |
project
- Description: The project root object
| Name | Kind | Description |
|---|---|---|
| charts | scalar | Prints the charts configured in the Dashboard page |
| Description | scalar | Description text of the entry |
| Devices | list | Device entries of the project |
| Hyperlinks | scalar | Referenced hyperlinks of the entry |
| Image | scalar | Project image |
| MobileApps | list | Mobile app entries of the project |
| Modules | list | Project module entries |
| Name | scalar | Display name of the entry |
| Participants | list | Project participants including role and contact data |
| ProjectName | scalar | Project name defined by user |
| ProjectVersion | scalar | Latest project version label |
| riskMatrix | scalar | Prints the risk matrix of the default risk method |
| SystemsUnderConsideration | scalar | System under consideration summary |
| SystemUnderConsideration | scalar | System under consideration summary |
| UserVersions | list | Structured project version history entries |
| Workshops | list | Recorded workshop entries including date, participants, and notes |
softwareDiagrams
- Description: Software model stacks exported as diagram-like entries
| Name | Kind | Description |
|---|---|---|
| attackScenarios | list | Attack Scenarios |
| AttackScenarios | list | List of related attack scenarios |
| countermeasures | list | Countermeasures |
| Countermeasures | list | List of related countermeasures |
| Description | scalar | Description text of the entry |
| DiagramType | scalar | Type of the diagram entry |
| Hyperlinks | scalar | Referenced hyperlinks of the entry |
| Image | scalar | Rendered image payload of the diagram |
| Name | scalar | Display name of the entry |
| Path | scalar | Source path or location label of the diagram |
systemThreats
- Description: All system threats
| Name | Kind | Description |
|---|---|---|
| AffectedAssetObjects | scalar | Related assets |
| attackScenarios | list | Related attack scenarios |
| AttackScenarios | list | Attack scenarios linked to the entry |
| Description | scalar | Description text of the entry |
| Hyperlinks | scalar | Referenced hyperlinks of the entry |
| Identifier | scalar | Unique reference identifier of the entry |
| Impact | scalar | Maximum impact value of the threat |
| ImpactCats | scalar | Related Auswirkungskategorien |
| ImpactPerProtectionGoal | scalar | Impact assessment per protection goal |
| LongName | scalar | Full display name including prefix, number, and name. |
| MaxRisk | scalar | Maximum risk value of the entry |
| Name | scalar | Display name of the entry |
| Number | scalar | Number shown for the entry |
| ThreatCategory | scalar | Assigned threat category |
testCases
- Description: All test cases
| Name | Kind | Description |
|---|---|---|
| Description | scalar | Description text of the entry |
| Hyperlinks | scalar | Referenced hyperlinks of the entry |
| Identifier | scalar | Unique reference identifier of the entry |
| Images | list | Linked evidence images |
| LinkedElements | list | Linked model elements |
| LinkedMeasures | list | Linked countermeasures |
| LinkedScenarios | list | Linked Attack Scenarios |
| LongName | scalar | Full display name including prefix, number, and name. |
| Name | scalar | Display name of the entry |
| Number | scalar | Number shown for the entry |
| PreConditions | list | Preconditions of the test case |
| Status | scalar | Status (Pass/Fail) of the entry |
| Steps | list | Execution steps of the test case |
| Summary | list | Summary/result entries of the test case |
| TestData | list | Input and expected test data |
| Version | scalar | Version of the test case |
threatSources
- Description: All threat sources
| Name | Kind | Description |
|---|---|---|
| Capabilities | list | Capabilities assigned to the threat source |
| Description | scalar | Description text of the entry |
| Hyperlinks | scalar | Referenced hyperlinks of the entry |
| Identifier | scalar | Unique reference identifier of the entry |
| Likelihood | scalar | Likelihood value of the threat source |
| LongName | scalar | Full display name including prefix, number, and name. |
| Motive | list | Motivation characteristics of the threat source |
| Name | scalar | Display name of the entry |
| Number | scalar | Number shown for the entry |
useCaseDiagrams
- Description: All use case diagrams
| Name | Kind | Description |
|---|---|---|
| attackScenarios | list | Attack Scenarios |
| AttackScenarios | list | List of related attack scenarios |
| countermeasures | list | Countermeasures |
| Countermeasures | list | List of related countermeasures |
| Description | scalar | Description text of the entry |
| DiagramType | scalar | Type of the diagram entry |
| Hyperlinks | scalar | Referenced hyperlinks of the entry |
| Image | scalar | Rendered image payload of the diagram |
| Name | scalar | Display name of the entry |
| Path | scalar | Source path or location label of the diagram |
Entity Properties
| Entity | Property | Kind |
|---|---|---|
| Project | charts | scalar |
| Project | Description | scalar |
| Project | Devices | list |
| Project | Hyperlinks | scalar |
| Project | Image | scalar |
| Project | MobileApps | list |
| Project | Modules | list |
| Project | Name | scalar |
| Project | Participants | list |
| Project | ProjectName | scalar |
| Project | ProjectVersion | scalar |
| Project | riskMatrix | scalar |
| Project | SystemsUnderConsideration | scalar |
| Project | SystemUnderConsideration | scalar |
| Project | UserVersions | list |
| Project | Workshops | list |
| Config | RiskAcceptanceCriteria | scalar |
| Config | RiskAcceptanceLevel | scalar |
| Assumptions | AssumptionCategories | scalar |
| Assumptions | Automations | scalar |
| Assumptions | Categories | scalar |
| Assumptions | Definitions | scalar |
| Assumptions | Description | scalar |
| Assumptions | Hyperlinks | scalar |
| Assumptions | Identifier | scalar |
| Assumptions | LongName | scalar |
| Assumptions | Name | scalar |
| Assumptions | Number | scalar |
| Assumptions | Responsible | scalar |
| Assumptions | Validated | scalar |
| Assets | Description | scalar |
| Assets | Hyperlinks | scalar |
| Assets | Identifier | scalar |
| Assets | ImpactCats | scalar |
| Assets | ImpactPerProtectionGoal | scalar |
| Assets | LongName | scalar |
| Assets | Name | scalar |
| Assets | Number | scalar |
| Assets | Sensitivity | scalar |
| Assets | Type | scalar |
| AttackScenario | AffectedAssetObjects | scalar |
| AttackScenario | AttackVector | scalar |
| AttackScenario | CAPECID | scalar |
| AttackScenario | CAPECLink | scalar |
| AttackScenario | Countermeasures | scalar |
| AttackScenario | CvssNotes31 | scalar |
| AttackScenario | CvssNotes40 | scalar |
| AttackScenario | CvssScore31 | scalar |
| AttackScenario | CvssScore40 | scalar |
| AttackScenario | CvssVector31 | scalar |
| AttackScenario | CvssVector40 | scalar |
| AttackScenario | CWEID | scalar |
| AttackScenario | CWELink | scalar |
| AttackScenario | Description | scalar |
| AttackScenario | Diagram | scalar |
| AttackScenario | EMB3DID | scalar |
| AttackScenario | EMB3DLink | scalar |
| AttackScenario | Hyperlinks | scalar |
| AttackScenario | Identifier | scalar |
| AttackScenario | LinkedRequirements | scalar |
| AttackScenario | LinkedScenarios | scalar |
| AttackScenario | LinkedTestCases | scalar |
| AttackScenario | LongName | scalar |
| AttackScenario | MyTags | scalar |
| AttackScenario | Name | scalar |
| AttackScenario | Number | scalar |
| AttackScenario | OwaspScore | scalar |
| AttackScenario | OwaspVector | scalar |
| AttackScenario | ProtectionGoals | scalar |
| AttackScenario | RemainingCvssNotes31 | scalar |
| AttackScenario | RemainingCvssNotes40 | scalar |
| AttackScenario | RemainingCvssScore31 | scalar |
| AttackScenario | RemainingCvssScore40 | scalar |
| AttackScenario | RemainingCvssVector31 | scalar |
| AttackScenario | RemainingCvssVector40 | scalar |
| AttackScenario | RemainingOwaspScore | scalar |
| AttackScenario | RemainingOwaspVector | scalar |
| AttackScenario | RiskStrategy | scalar |
| AttackScenario | RiskStrategyReason | scalar |
| AttackScenario | RNotesCVSS | scalar |
| AttackScenario | RNotesCVSS40 | scalar |
| AttackScenario | RNotesCVSSdefault | scalar |
| AttackScenario | RRNotesCVSS | scalar |
| AttackScenario | RRNotesCVSS40 | scalar |
| AttackScenario | RRNotesCVSSdefault | scalar |
| AttackScenario | RRScoreCVSS | scalar |
| AttackScenario | RRScoreCVSS40 | scalar |
| AttackScenario | RRScoreCVSSdefault | scalar |
| AttackScenario | RRScoreOwaspRR | scalar |
| AttackScenario | RRVectorCVSS | scalar |
| AttackScenario | RRVectorCVSS40 | scalar |
| AttackScenario | RRVectorCVSSdefault | scalar |
| AttackScenario | RRVectorOwaspRR | scalar |
| AttackScenario | RScoreCVSS | scalar |
| AttackScenario | RScoreCVSS40 | scalar |
| AttackScenario | RScoreCVSSdefault | scalar |
| AttackScenario | RScoreOwaspRR | scalar |
| AttackScenario | RVectorCVSS | scalar |
| AttackScenario | RVectorCVSS40 | scalar |
| AttackScenario | RVectorCVSSdefault | scalar |
| AttackScenario | RVectorOwaspRR | scalar |
| AttackScenario | Status | scalar |
| AttackScenario | SystemThreats | scalar |
| AttackScenario | Target | scalar |
| AttackScenario | Targets | scalar |
| AttackScenario | TargetType | scalar |
| AttackScenario | ThreatCategories | scalar |
| AttackScenario | ThreatSources | scalar |
| AttackScenario | ThreatState | scalar |
| AttackScenario | TreatmentState | scalar |
| AttackScenario | TreatmentStatus | scalar |
| Countermeasure | AttackScenarios | list |
| Countermeasure | AttackVectors | scalar |
| Countermeasure | Control | scalar |
| Countermeasure | Description | scalar |
| Countermeasure | Diagram | scalar |
| Countermeasure | EMB3DIDs | scalar |
| Countermeasure | Hyperlinks | scalar |
| Countermeasure | Identifier | scalar |
| Countermeasure | LinkedRequirements | scalar |
| Countermeasure | LinkedTestCases | scalar |
| Countermeasure | LongName | scalar |
| Countermeasure | MaxRisk | scalar |
| Countermeasure | MitigationProcess | scalar |
| Countermeasure | MitigationState | scalar |
| Countermeasure | MyTags | scalar |
| Countermeasure | Name | scalar |
| Countermeasure | Number | scalar |
| Countermeasure | Status | scalar |
| Countermeasure | Targets | scalar |
| MitigationProcess | AttackScenarios | scalar |
| MitigationProcess | Countermeasures | scalar |
| MitigationProcess | Description | scalar |
| MitigationProcess | Hyperlinks | scalar |
| MitigationProcess | Identifier | scalar |
| MitigationProcess | LongName | scalar |
| MitigationProcess | MaxRisk | scalar |
| MitigationProcess | MitigationProcessState | scalar |
| MitigationProcess | Name | scalar |
| MitigationProcess | Notes | list |
| MitigationProcess | Number | scalar |
| MitigationProcess | Progress | scalar |
| MitigationProcess | Status | scalar |
| MitigationProcess | Tasks | list |
| SystemThreat | AffectedAssetObjects | scalar |
| SystemThreat | attackScenarios | list |
| SystemThreat | AttackScenarios | list |
| SystemThreat | Description | scalar |
| SystemThreat | Hyperlinks | scalar |
| SystemThreat | Identifier | scalar |
| SystemThreat | Impact | scalar |
| SystemThreat | ImpactCats | scalar |
| SystemThreat | ImpactPerProtectionGoal | scalar |
| SystemThreat | LongName | scalar |
| SystemThreat | MaxRisk | scalar |
| SystemThreat | Name | scalar |
| SystemThreat | Number | scalar |
| SystemThreat | ThreatCategory | scalar |
| ThreatSources | Capabilities | list |
| ThreatSources | Description | scalar |
| ThreatSources | Hyperlinks | scalar |
| ThreatSources | Identifier | scalar |
| ThreatSources | Likelihood | scalar |
| ThreatSources | LongName | scalar |
| ThreatSources | Motive | list |
| ThreatSources | Name | scalar |
| ThreatSources | Number | scalar |
| TestCase | Description | scalar |
| TestCase | Hyperlinks | scalar |
| TestCase | Identifier | scalar |
| TestCase | Images | list |
| TestCase | LinkedElements | list |
| TestCase | LinkedMeasures | list |
| TestCase | LinkedScenarios | list |
| TestCase | LongName | scalar |
| TestCase | Name | scalar |
| TestCase | Number | scalar |
| TestCase | PreConditions | list |
| TestCase | Status | scalar |
| TestCase | Steps | list |
| TestCase | Summary | list |
| TestCase | TestData | list |
| TestCase | Version | scalar |
| Checklist | Description | scalar |
| Checklist | Hyperlinks | scalar |
| Checklist | Level1 | scalar |
| Checklist | Level2 | scalar |
| Checklist | Level3 | scalar |
| Checklist | Level4 | scalar |
| Checklist | Level5 | scalar |
| Checklist | LinkedMeasures | list |
| Checklist | LinkedScenarios | list |
| Checklist | Name | scalar |
| Checklist | Notes | scalar |
| Checklist | Prefix | scalar |
| Checklist | PrefixPath | scalar |
| Checklist | TestReports | scalar |
| RequirementValue | Description | scalar |
| RequirementValue | Hyperlinks | scalar |
| RequirementValue | Justification | scalar |
| RequirementValue | LinkedMeasures | list |
| RequirementValue | LinkedScenarios | list |
| RequirementValue | Name | scalar |
| RequirementValue | Notes | scalar |
| RequirementValue | RelatedMeasures | list |
| RequirementValue | Type | scalar |
| RequirementValue | Value | scalar |
| RequirementType | Description | scalar |
| RequirementType | Explanation | scalar |
| RequirementType | Hyperlinks | scalar |
| RequirementType | Name | scalar |
| RequirementType | Prefix | scalar |
| RequirementType | PrefixPath | scalar |
| Diagram | attackScenarios | list |
| Diagram | AttackScenarios | list |
| Diagram | countermeasures | list |
| Diagram | Countermeasures | list |
| Diagram | Description | scalar |
| Diagram | DiagramType | scalar |
| Diagram | Hyperlinks | scalar |
| Diagram | Image | scalar |
| Diagram | Name | scalar |
| Diagram | Path | scalar |
| Document | Date | scalar |
| Document | TableOfContents | scalar |
| Document | TTModelerLogo | scalar |
| Document | TTModelerVersion | scalar |
Dynamic Property Patterns
These patterns are configuration dependent and not expanded with project-specific IDs in this generic reference.
| Entity | Pattern |
|---|---|
| Assets | PG{protectionGoalID} |
| Assets | IC{impactCategoryID} |
| AttackScenario | R{metricID} |
| AttackScenario | NR{metricID} |
| AttackScenario | RR{metricID} |
| AttackScenario | NRR{metricID} |
Dynamic Root Variable Patterns
These dynamic lookups are available on analysis scope root variables and aliases.
| Variable | Pattern | Result |
|---|---|---|
| characterizationScope | [" |
object with Name and Value |
| objectivesImpact | [" |
object with Name and Value |
| checklists | [" |
Checklist entry (same fields as when iterating with a for loop) |