Custom Report Template Reference
Generated for app version: 1.14.0
Root Variables
| Variable | Description |
|---|---|
| assetGroups | Asset group summary entries including generated image and display fields. |
| assets | All assets in the project. |
| assumptions | All project assumptions. |
| attackScenarios | Applicable attack scenarios. |
| attackScenariosAll | All attack scenarios including not applicable entries. |
| attackScenariosNotApplicable | Attack scenarios marked as not applicable. |
| characterizationScope | Characterization scope analysis fields. |
| checklists | Checklist groups enriched with module, current level and generated requirements table. |
| contextDiagrams | All context diagrams. |
| countermeasures | Applicable countermeasures. |
| countermeasuresAll | All countermeasures including not applicable entries. |
| countermeasuresNotApplicable | Countermeasures marked as not applicable. |
| dataFlowDiagrams | All data flow diagrams. |
| diagrams | All diagrams in the project. |
| document | Document metadata like date, app version and logo. |
| hardwareDiagrams | All hardware diagrams. |
| mitigationProcesses | All mitigation processes. |
| objectivesImpact | Object impact analysis fields. |
| processDiagrams | Process model stacks exported as diagram-like entries. |
| project | The project root object. |
| softwareDiagrams | Software model stacks exported as diagram-like entries. |
| systemThreats | All system threats. |
| testCases | All test cases. |
| threatSources | All threat sources. |
| useCaseDiagrams | All use case diagrams. |
Root Aliases
| Alias | Resolves To |
|---|---|
| charScope | characterizationScope |
| dfDiagrams | dataFlowDiagrams |
| doc | document |
| hwDiagrams | hardwareDiagrams |
| measures | countermeasures |
| objImpact | objectivesImpact |
| procDiagrams | processDiagrams |
| scenarios | attackScenarios |
| swDiagrams | softwareDiagrams |
| threatActors | threatSources |
Root Variable Details
assetGroups
- Description: Asset group summary entries including generated image and display fields.
| Name | Kind | Description |
|---|---|---|
| Name | scalar | Name of the asset group. |
| Image | scalar | Rendered overview image (HTML img tag) for the asset group. |
| assets | list |
Assets contained in the group as exported Asset entries. |
assets
- Description: All assets in the project.
| Name | Kind | Description |
|---|---|---|
| Description | scalar | Description text of the entry. |
| Hyperlinks | scalar | Referenced hyperlinks of the entry. |
| Identifier | scalar | Unique reference identifier of the entry. |
| ImpactCats | scalar | Impact categories assigned to the asset. |
| ImpactPerProtectionGoal | scalar | Impact values grouped by protection goal. |
| Name | scalar | Display name of the entry. |
| Number | scalar | Number shown for the entry. |
| Sensitivity | scalar | Sensitivity level for data assets. |
| Type | scalar | User-facing type label of the entry (for example Asset or Data). |
assumptions
- Description: All project assumptions.
| Name | Kind | Description |
|---|---|---|
| AssumptionCategories | scalar | Assigned categories for the assumption. |
| Automations | scalar | Configured risk metric automation values. |
| Categories | scalar | Assigned categories for the assumption. |
| Definitions | scalar | Configured risk metric automation values. |
| Description | scalar | Description text of the entry. |
| Hyperlinks | scalar | Referenced hyperlinks of the entry. |
| Identifier | scalar | Unique reference identifier of the entry. |
| Name | scalar | Display name of the entry. |
| Number | scalar | Number shown for the entry. |
| Responsible | scalar | Responsible person or role. |
| Validated | scalar | Validation state of the assumption. |
attackScenarios
- Description: Applicable attack scenarios.
- Aliases: scenarios
| Name | Kind | Description |
|---|---|---|
| AffectedAssetObjects | scalar | Affected assets and objects linked to the entry. |
| AttackVector | scalar | Attack vector classification. |
| CAPECID | scalar | CAPEC identifier of the linked attack vector. |
| CAPECLink | scalar | CAPEC Link |
| Countermeasures | scalar | Countermeasures linked to the entry. |
| CvssNotes31 | scalar | CVSS/OWASP risk value, vector, score, or note. |
| CvssNotes40 | scalar | CVSS/OWASP risk value, vector, score, or note. |
| CvssScore31 | scalar | CVSS/OWASP risk value, vector, score, or note. |
| CvssScore40 | scalar | CVSS/OWASP risk value, vector, score, or note. |
| CvssVector31 | scalar | CVSS/OWASP risk value, vector, score, or note. |
| CvssVector40 | scalar | CVSS/OWASP risk value, vector, score, or note. |
| CWEID | scalar | CWE identifier of the linked attack vector. |
| CWELink | scalar | CWE Link |
| Description | scalar | Description text of the entry. |
| Diagram | scalar | Diagram context of the entry. |
| EMB3DID | scalar | EMB3D identifier of the linked attack vector. |
| EMB3DLink | scalar | EMB3 D Link |
| Hyperlinks | scalar | Referenced hyperlinks of the entry. |
| Identifier | scalar | Unique reference identifier of the entry. |
| LinkedRequirements | scalar | Requirements linked to the entry. |
| LinkedScenarios | scalar | Attack scenarios linked to the entry. |
| LinkedTestCases | scalar | Test cases linked to the entry. |
| MyTags | scalar | Tags assigned to the entry. |
| Name | scalar | Display name of the entry. |
| Number | scalar | Number shown for the entry. |
| OwaspScore | scalar | CVSS/OWASP risk value, vector, score, or note. |
| OwaspVector | scalar | CVSS/OWASP risk value, vector, score, or note. |
| ProtectionGoals | scalar | Protection goals affected by the scenario. |
| RemainingCvssNotes31 | scalar | CVSS/OWASP risk value, vector, score, or note. |
| RemainingCvssNotes40 | scalar | CVSS/OWASP risk value, vector, score, or note. |
| RemainingCvssScore31 | scalar | CVSS/OWASP risk value, vector, score, or note. |
| RemainingCvssScore40 | scalar | CVSS/OWASP risk value, vector, score, or note. |
| RemainingCvssVector31 | scalar | CVSS/OWASP risk value, vector, score, or note. |
| RemainingCvssVector40 | scalar | CVSS/OWASP risk value, vector, score, or note. |
| RemainingOwaspScore | scalar | CVSS/OWASP risk value, vector, score, or note. |
| RemainingOwaspVector | scalar | CVSS/OWASP risk value, vector, score, or note. |
| RiskStrategy | scalar | Selected risk strategy. |
| RiskStrategyReason | scalar | Reasoning and notes for the selected risk strategy. |
| RNotesCVSS | scalar | CVSS/OWASP risk value, vector, score, or note. |
| RNotesCVSS40 | scalar | CVSS/OWASP risk value, vector, score, or note. |
| RNotesCVSSdefault | scalar | CVSS/OWASP risk value, vector, score, or note. |
| RRNotesCVSS | scalar | CVSS/OWASP risk value, vector, score, or note. |
| RRNotesCVSS40 | scalar | CVSS/OWASP risk value, vector, score, or note. |
| RRNotesCVSSdefault | scalar | CVSS/OWASP risk value, vector, score, or note. |
| RRScoreCVSS | scalar | CVSS/OWASP risk value, vector, score, or note. |
| RRScoreCVSS40 | scalar | CVSS/OWASP risk value, vector, score, or note. |
| RRScoreCVSSdefault | scalar | CVSS/OWASP risk value, vector, score, or note. |
| RRScoreOwaspRR | scalar | CVSS/OWASP risk value, vector, score, or note. |
| RRVectorCVSS | scalar | CVSS/OWASP risk value, vector, score, or note. |
| RRVectorCVSS40 | scalar | CVSS/OWASP risk value, vector, score, or note. |
| RRVectorCVSSdefault | scalar | CVSS/OWASP risk value, vector, score, or note. |
| RRVectorOwaspRR | scalar | CVSS/OWASP risk value, vector, score, or note. |
| RScoreCVSS | scalar | CVSS/OWASP risk value, vector, score, or note. |
| RScoreCVSS40 | scalar | CVSS/OWASP risk value, vector, score, or note. |
| RScoreCVSSdefault | scalar | CVSS/OWASP risk value, vector, score, or note. |
| RScoreOwaspRR | scalar | CVSS/OWASP risk value, vector, score, or note. |
| RVectorCVSS | scalar | CVSS/OWASP risk value, vector, score, or note. |
| RVectorCVSS40 | scalar | CVSS/OWASP risk value, vector, score, or note. |
| RVectorCVSSdefault | scalar | CVSS/OWASP risk value, vector, score, or note. |
| RVectorOwaspRR | scalar | CVSS/OWASP risk value, vector, score, or note. |
| Status | scalar | Current status of the entry. |
| SystemThreats | scalar | System threats linked to the scenario. |
| Target | scalar | Primary target object of the scenario. |
| Targets | scalar | All target objects linked to the scenario. |
| TargetType | scalar | Type of the selected target object. |
| ThreatCategories | scalar | Threat categories for grouping and classifying threats. |
| ThreatSources | scalar | Threat sources linked to the scenario. |
| ThreatState | scalar | Threat State |
| TreatmentState | scalar | Treatment State |
| TreatmentStatus | scalar | Treatment status of the entry. |
attackScenariosAll
- Description: All attack scenarios including not applicable entries.
| Name | Kind | Description |
|---|---|---|
| AffectedAssetObjects | scalar | Affected assets and objects linked to the entry. |
| AttackVector | scalar | Attack vector classification. |
| CAPECID | scalar | CAPEC identifier of the linked attack vector. |
| CAPECLink | scalar | CAPEC Link |
| Countermeasures | scalar | Countermeasures linked to the entry. |
| CvssNotes31 | scalar | CVSS/OWASP risk value, vector, score, or note. |
| CvssNotes40 | scalar | CVSS/OWASP risk value, vector, score, or note. |
| CvssScore31 | scalar | CVSS/OWASP risk value, vector, score, or note. |
| CvssScore40 | scalar | CVSS/OWASP risk value, vector, score, or note. |
| CvssVector31 | scalar | CVSS/OWASP risk value, vector, score, or note. |
| CvssVector40 | scalar | CVSS/OWASP risk value, vector, score, or note. |
| CWEID | scalar | CWE identifier of the linked attack vector. |
| CWELink | scalar | CWE Link |
| Description | scalar | Description text of the entry. |
| Diagram | scalar | Diagram context of the entry. |
| EMB3DID | scalar | EMB3D identifier of the linked attack vector. |
| EMB3DLink | scalar | EMB3 D Link |
| Hyperlinks | scalar | Referenced hyperlinks of the entry. |
| Identifier | scalar | Unique reference identifier of the entry. |
| LinkedRequirements | scalar | Requirements linked to the entry. |
| LinkedScenarios | scalar | Attack scenarios linked to the entry. |
| LinkedTestCases | scalar | Test cases linked to the entry. |
| MyTags | scalar | Tags assigned to the entry. |
| Name | scalar | Display name of the entry. |
| Number | scalar | Number shown for the entry. |
| OwaspScore | scalar | CVSS/OWASP risk value, vector, score, or note. |
| OwaspVector | scalar | CVSS/OWASP risk value, vector, score, or note. |
| ProtectionGoals | scalar | Protection goals affected by the scenario. |
| RemainingCvssNotes31 | scalar | CVSS/OWASP risk value, vector, score, or note. |
| RemainingCvssNotes40 | scalar | CVSS/OWASP risk value, vector, score, or note. |
| RemainingCvssScore31 | scalar | CVSS/OWASP risk value, vector, score, or note. |
| RemainingCvssScore40 | scalar | CVSS/OWASP risk value, vector, score, or note. |
| RemainingCvssVector31 | scalar | CVSS/OWASP risk value, vector, score, or note. |
| RemainingCvssVector40 | scalar | CVSS/OWASP risk value, vector, score, or note. |
| RemainingOwaspScore | scalar | CVSS/OWASP risk value, vector, score, or note. |
| RemainingOwaspVector | scalar | CVSS/OWASP risk value, vector, score, or note. |
| RiskStrategy | scalar | Selected risk strategy. |
| RiskStrategyReason | scalar | Reasoning and notes for the selected risk strategy. |
| RNotesCVSS | scalar | CVSS/OWASP risk value, vector, score, or note. |
| RNotesCVSS40 | scalar | CVSS/OWASP risk value, vector, score, or note. |
| RNotesCVSSdefault | scalar | CVSS/OWASP risk value, vector, score, or note. |
| RRNotesCVSS | scalar | CVSS/OWASP risk value, vector, score, or note. |
| RRNotesCVSS40 | scalar | CVSS/OWASP risk value, vector, score, or note. |
| RRNotesCVSSdefault | scalar | CVSS/OWASP risk value, vector, score, or note. |
| RRScoreCVSS | scalar | CVSS/OWASP risk value, vector, score, or note. |
| RRScoreCVSS40 | scalar | CVSS/OWASP risk value, vector, score, or note. |
| RRScoreCVSSdefault | scalar | CVSS/OWASP risk value, vector, score, or note. |
| RRScoreOwaspRR | scalar | CVSS/OWASP risk value, vector, score, or note. |
| RRVectorCVSS | scalar | CVSS/OWASP risk value, vector, score, or note. |
| RRVectorCVSS40 | scalar | CVSS/OWASP risk value, vector, score, or note. |
| RRVectorCVSSdefault | scalar | CVSS/OWASP risk value, vector, score, or note. |
| RRVectorOwaspRR | scalar | CVSS/OWASP risk value, vector, score, or note. |
| RScoreCVSS | scalar | CVSS/OWASP risk value, vector, score, or note. |
| RScoreCVSS40 | scalar | CVSS/OWASP risk value, vector, score, or note. |
| RScoreCVSSdefault | scalar | CVSS/OWASP risk value, vector, score, or note. |
| RScoreOwaspRR | scalar | CVSS/OWASP risk value, vector, score, or note. |
| RVectorCVSS | scalar | CVSS/OWASP risk value, vector, score, or note. |
| RVectorCVSS40 | scalar | CVSS/OWASP risk value, vector, score, or note. |
| RVectorCVSSdefault | scalar | CVSS/OWASP risk value, vector, score, or note. |
| RVectorOwaspRR | scalar | CVSS/OWASP risk value, vector, score, or note. |
| Status | scalar | Current status of the entry. |
| SystemThreats | scalar | System threats linked to the scenario. |
| Target | scalar | Primary target object of the scenario. |
| Targets | scalar | All target objects linked to the scenario. |
| TargetType | scalar | Type of the selected target object. |
| ThreatCategories | scalar | Threat categories for grouping and classifying threats. |
| ThreatSources | scalar | Threat sources linked to the scenario. |
| ThreatState | scalar | Threat State |
| TreatmentState | scalar | Treatment State |
| TreatmentStatus | scalar | Treatment status of the entry. |
attackScenariosNotApplicable
- Description: Attack scenarios marked as not applicable.
| Name | Kind | Description |
|---|---|---|
| AffectedAssetObjects | scalar | Affected assets and objects linked to the entry. |
| AttackVector | scalar | Attack vector classification. |
| CAPECID | scalar | CAPEC identifier of the linked attack vector. |
| CAPECLink | scalar | CAPEC Link |
| Countermeasures | scalar | Countermeasures linked to the entry. |
| CvssNotes31 | scalar | CVSS/OWASP risk value, vector, score, or note. |
| CvssNotes40 | scalar | CVSS/OWASP risk value, vector, score, or note. |
| CvssScore31 | scalar | CVSS/OWASP risk value, vector, score, or note. |
| CvssScore40 | scalar | CVSS/OWASP risk value, vector, score, or note. |
| CvssVector31 | scalar | CVSS/OWASP risk value, vector, score, or note. |
| CvssVector40 | scalar | CVSS/OWASP risk value, vector, score, or note. |
| CWEID | scalar | CWE identifier of the linked attack vector. |
| CWELink | scalar | CWE Link |
| Description | scalar | Description text of the entry. |
| Diagram | scalar | Diagram context of the entry. |
| EMB3DID | scalar | EMB3D identifier of the linked attack vector. |
| EMB3DLink | scalar | EMB3 D Link |
| Hyperlinks | scalar | Referenced hyperlinks of the entry. |
| Identifier | scalar | Unique reference identifier of the entry. |
| LinkedRequirements | scalar | Requirements linked to the entry. |
| LinkedScenarios | scalar | Attack scenarios linked to the entry. |
| LinkedTestCases | scalar | Test cases linked to the entry. |
| MyTags | scalar | Tags assigned to the entry. |
| Name | scalar | Display name of the entry. |
| Number | scalar | Number shown for the entry. |
| OwaspScore | scalar | CVSS/OWASP risk value, vector, score, or note. |
| OwaspVector | scalar | CVSS/OWASP risk value, vector, score, or note. |
| ProtectionGoals | scalar | Protection goals affected by the scenario. |
| RemainingCvssNotes31 | scalar | CVSS/OWASP risk value, vector, score, or note. |
| RemainingCvssNotes40 | scalar | CVSS/OWASP risk value, vector, score, or note. |
| RemainingCvssScore31 | scalar | CVSS/OWASP risk value, vector, score, or note. |
| RemainingCvssScore40 | scalar | CVSS/OWASP risk value, vector, score, or note. |
| RemainingCvssVector31 | scalar | CVSS/OWASP risk value, vector, score, or note. |
| RemainingCvssVector40 | scalar | CVSS/OWASP risk value, vector, score, or note. |
| RemainingOwaspScore | scalar | CVSS/OWASP risk value, vector, score, or note. |
| RemainingOwaspVector | scalar | CVSS/OWASP risk value, vector, score, or note. |
| RiskStrategy | scalar | Selected risk strategy. |
| RiskStrategyReason | scalar | Reasoning and notes for the selected risk strategy. |
| RNotesCVSS | scalar | CVSS/OWASP risk value, vector, score, or note. |
| RNotesCVSS40 | scalar | CVSS/OWASP risk value, vector, score, or note. |
| RNotesCVSSdefault | scalar | CVSS/OWASP risk value, vector, score, or note. |
| RRNotesCVSS | scalar | CVSS/OWASP risk value, vector, score, or note. |
| RRNotesCVSS40 | scalar | CVSS/OWASP risk value, vector, score, or note. |
| RRNotesCVSSdefault | scalar | CVSS/OWASP risk value, vector, score, or note. |
| RRScoreCVSS | scalar | CVSS/OWASP risk value, vector, score, or note. |
| RRScoreCVSS40 | scalar | CVSS/OWASP risk value, vector, score, or note. |
| RRScoreCVSSdefault | scalar | CVSS/OWASP risk value, vector, score, or note. |
| RRScoreOwaspRR | scalar | CVSS/OWASP risk value, vector, score, or note. |
| RRVectorCVSS | scalar | CVSS/OWASP risk value, vector, score, or note. |
| RRVectorCVSS40 | scalar | CVSS/OWASP risk value, vector, score, or note. |
| RRVectorCVSSdefault | scalar | CVSS/OWASP risk value, vector, score, or note. |
| RRVectorOwaspRR | scalar | CVSS/OWASP risk value, vector, score, or note. |
| RScoreCVSS | scalar | CVSS/OWASP risk value, vector, score, or note. |
| RScoreCVSS40 | scalar | CVSS/OWASP risk value, vector, score, or note. |
| RScoreCVSSdefault | scalar | CVSS/OWASP risk value, vector, score, or note. |
| RScoreOwaspRR | scalar | CVSS/OWASP risk value, vector, score, or note. |
| RVectorCVSS | scalar | CVSS/OWASP risk value, vector, score, or note. |
| RVectorCVSS40 | scalar | CVSS/OWASP risk value, vector, score, or note. |
| RVectorCVSSdefault | scalar | CVSS/OWASP risk value, vector, score, or note. |
| RVectorOwaspRR | scalar | CVSS/OWASP risk value, vector, score, or note. |
| Status | scalar | Current status of the entry. |
| SystemThreats | scalar | System threats linked to the scenario. |
| Target | scalar | Primary target object of the scenario. |
| Targets | scalar | All target objects linked to the scenario. |
| TargetType | scalar | Type of the selected target object. |
| ThreatCategories | scalar | Threat categories for grouping and classifying threats. |
| ThreatSources | scalar | Threat sources linked to the scenario. |
| ThreatState | scalar | Threat State |
| TreatmentState | scalar | Treatment State |
| TreatmentStatus | scalar | Treatment status of the entry. |
characterizationScope
- Description: Characterization scope analysis fields.
- Aliases: charScope
| Name | Kind | Description |
|---|---|---|
checklists
- Description: Checklist groups enriched with module, current level and generated requirements table.
| Name | Kind | Description |
|---|---|---|
| ModuleName | scalar | Module Name |
| Name | scalar | Display name of the entry. |
| CurrentLevel | scalar | Current Level |
| SummaryTable | scalar | Summary Table |
| RequirementsTable | scalar | Requirements Table |
| requirements | list |
Requirements |
contextDiagrams
- Description: All context diagrams.
| Name | Kind | Description |
|---|---|---|
| attackScenarios | list | Attack Scenarios |
| AttackScenarios | list | Attack Scenarios |
| countermeasures | list | Countermeasures |
| Countermeasures | list | Countermeasures |
| DiagramType | scalar | Type of the diagram entry. |
| Image | scalar | Rendered image payload of the diagram. |
| Name | scalar | Display name of the entry. |
| Path | scalar | Source path or location label of the diagram. |
countermeasures
- Description: Applicable countermeasures.
- Aliases: measures
| Name | Kind | Description |
|---|---|---|
| AttackScenarios | list | Attack Scenarios |
| AttackVectors | scalar | Attack vectors covered by the countermeasure. |
| Control | scalar | Mapped control entry. |
| Description | scalar | Description text of the entry. |
| Diagram | scalar | Diagram |
| EMB3DIDs | scalar | Linked EMB3D mitigation identifiers from the mapped control. |
| Hyperlinks | scalar | Referenced hyperlinks of the entry. |
| Identifier | scalar | Unique reference identifier of the entry. |
| LinkedRequirements | scalar | Requirements linked to the countermeasure. |
| LinkedTestCases | scalar | Test cases linked to the countermeasure. |
| MaxRisk | scalar | Maximum risk across linked attack scenarios. |
| MitigationProcess | scalar | Assigned mitigation process. |
| MitigationState | scalar | Mitigation State |
| MyTags | scalar | My Tags |
| Name | scalar | Display name of the entry. |
| Number | scalar | Number shown for the entry. |
| Status | scalar | Status |
| Targets | scalar | Targets |
countermeasuresAll
- Description: All countermeasures including not applicable entries.
| Name | Kind | Description |
|---|---|---|
| AttackScenarios | list | Attack Scenarios |
| AttackVectors | scalar | Attack vectors covered by the countermeasure. |
| Control | scalar | Mapped control entry. |
| Description | scalar | Description text of the entry. |
| Diagram | scalar | Diagram |
| EMB3DIDs | scalar | Linked EMB3D mitigation identifiers from the mapped control. |
| Hyperlinks | scalar | Referenced hyperlinks of the entry. |
| Identifier | scalar | Unique reference identifier of the entry. |
| LinkedRequirements | scalar | Requirements linked to the countermeasure. |
| LinkedTestCases | scalar | Test cases linked to the countermeasure. |
| MaxRisk | scalar | Maximum risk across linked attack scenarios. |
| MitigationProcess | scalar | Assigned mitigation process. |
| MitigationState | scalar | Mitigation State |
| MyTags | scalar | My Tags |
| Name | scalar | Display name of the entry. |
| Number | scalar | Number shown for the entry. |
| Status | scalar | Status |
| Targets | scalar | Targets |
countermeasuresNotApplicable
- Description: Countermeasures marked as not applicable.
| Name | Kind | Description |
|---|---|---|
| AttackScenarios | list | Attack Scenarios |
| AttackVectors | scalar | Attack vectors covered by the countermeasure. |
| Control | scalar | Mapped control entry. |
| Description | scalar | Description text of the entry. |
| Diagram | scalar | Diagram |
| EMB3DIDs | scalar | Linked EMB3D mitigation identifiers from the mapped control. |
| Hyperlinks | scalar | Referenced hyperlinks of the entry. |
| Identifier | scalar | Unique reference identifier of the entry. |
| LinkedRequirements | scalar | Requirements linked to the countermeasure. |
| LinkedTestCases | scalar | Test cases linked to the countermeasure. |
| MaxRisk | scalar | Maximum risk across linked attack scenarios. |
| MitigationProcess | scalar | Assigned mitigation process. |
| MitigationState | scalar | Mitigation State |
| MyTags | scalar | My Tags |
| Name | scalar | Display name of the entry. |
| Number | scalar | Number shown for the entry. |
| Status | scalar | Status |
| Targets | scalar | Targets |
dataFlowDiagrams
- Description: All data flow diagrams.
| Name | Kind | Description |
|---|---|---|
| attackScenarios | list | Attack Scenarios |
| AttackScenarios | list | Attack Scenarios |
| countermeasures | list | Countermeasures |
| Countermeasures | list | Countermeasures |
| DiagramType | scalar | Type of the diagram entry. |
| Image | scalar | Rendered image payload of the diagram. |
| Name | scalar | Display name of the entry. |
| Path | scalar | Source path or location label of the diagram. |
diagrams
- Description: All diagrams in the project.
| Name | Kind | Description |
|---|---|---|
| attackScenarios | list | Attack Scenarios |
| AttackScenarios | list | Attack Scenarios |
| countermeasures | list | Countermeasures |
| Countermeasures | list | Countermeasures |
| DiagramType | scalar | Type of the diagram entry. |
| Image | scalar | Rendered image payload of the diagram. |
| Name | scalar | Display name of the entry. |
| Path | scalar | Source path or location label of the diagram. |
document
- Description: Document metadata like date, app version and logo.
- Aliases: doc
| Name | Kind | Description |
|---|---|---|
| Date | scalar | Date |
| TTModelerVersion | scalar | TTModeler Version |
| TTModelerProVersion | scalar | TT Modeler Pro Version |
| TTModelerProLogo | scalar | TT Modeler Pro Logo |
hardwareDiagrams
- Description: All hardware diagrams.
| Name | Kind | Description |
|---|---|---|
| attackScenarios | list | Attack Scenarios |
| AttackScenarios | list | Attack Scenarios |
| countermeasures | list | Countermeasures |
| Countermeasures | list | Countermeasures |
| DiagramType | scalar | Type of the diagram entry. |
| Image | scalar | Rendered image payload of the diagram. |
| Name | scalar | Display name of the entry. |
| Path | scalar | Source path or location label of the diagram. |
mitigationProcesses
- Description: All mitigation processes.
| Name | Kind | Description |
|---|---|---|
| AttackScenarios | scalar | Attack Scenarios |
| Countermeasures | scalar | Countermeasures |
| Description | scalar | Description text of the entry. |
| Hyperlinks | scalar | Referenced hyperlinks of the entry. |
| Identifier | scalar | Unique reference identifier of the entry. |
| MaxRisk | scalar | Max. Risk |
| MitigationProcessState | scalar | Mitigation Process State |
| Name | scalar | Display name of the entry. |
| Notes | list | Notes of the entry. |
| Number | scalar | Number shown for the entry. |
| Progress | scalar | Progress information of the process. |
| Status | scalar | Status |
| Tasks | list | Task list of the process. |
objectivesImpact
- Description: Object impact analysis fields.
- Aliases: objImpact
| Name | Kind | Description |
|---|---|---|
processDiagrams
- Description: Process model stacks exported as diagram-like entries.
| Name | Kind | Description |
|---|---|---|
| attackScenarios | list | Attack Scenarios |
| AttackScenarios | list | Attack Scenarios |
| countermeasures | list | Countermeasures |
| Countermeasures | list | Countermeasures |
| DiagramType | scalar | Type of the diagram entry. |
| Image | scalar | Rendered image payload of the diagram. |
| Name | scalar | Display name of the entry. |
| Path | scalar | Source path or location label of the diagram. |
project
- Description: The project root object.
| Name | Kind | Description |
|---|---|---|
| Description | scalar | Description text of the entry. |
| Devices | list | Device entries of the project. |
| Hyperlinks | scalar | Referenced hyperlinks of the entry. |
| Image | scalar | Image |
| MobileApps | list | Mobile app entries of the project. |
| Modules | list | Project module entries. |
| Name | scalar | Display name of the entry. |
| Number | scalar | Number shown for the entry. |
| Participants | list | Project participants including role and contact data. |
| ProjectName | scalar | Project name defined by user |
| ProjectVersion | scalar | Latest project version label. |
| SystemsUnderConsideration | scalar | System under consideration summary. |
| SystemUnderConsideration | scalar | System under consideration summary. |
| UserVersions | list | Structured project version history entries. |
| Workshops | list | Recorded workshop entries including date, participants, and notes. |
softwareDiagrams
- Description: Software model stacks exported as diagram-like entries.
| Name | Kind | Description |
|---|---|---|
| attackScenarios | list | Attack Scenarios |
| AttackScenarios | list | Attack Scenarios |
| countermeasures | list | Countermeasures |
| Countermeasures | list | Countermeasures |
| DiagramType | scalar | Type of the diagram entry. |
| Image | scalar | Rendered image payload of the diagram. |
| Name | scalar | Display name of the entry. |
| Path | scalar | Source path or location label of the diagram. |
systemThreats
- Description: All system threats.
| Name | Kind | Description |
|---|---|---|
| AffectedAssetObjects | scalar | Affected Asset Objects |
| attackScenarios | list | Attack Scenarios |
| AttackScenarios | list | Attack scenarios linked to the entry. |
| Description | scalar | Description text of the entry. |
| Hyperlinks | scalar | Referenced hyperlinks of the entry. |
| Identifier | scalar | Unique reference identifier of the entry. |
| Impact | scalar | Maximum impact value of the threat. |
| ImpactCats | scalar | Impact Cats |
| ImpactPerProtectionGoal | scalar | Impact Per Protection Goal |
| MaxRisk | scalar | Maximum risk value of the entry. |
| Name | scalar | Display name of the entry. |
| Number | scalar | Number shown for the entry. |
| ThreatCategory | scalar | Assigned threat category. |
testCases
- Description: All test cases.
| Name | Kind | Description |
|---|---|---|
| Description | scalar | Description text of the entry. |
| Hyperlinks | scalar | Referenced hyperlinks of the entry. |
| Identifier | scalar | Unique reference identifier of the entry. |
| Images | list | Linked evidence images. |
| LinkedElements | list | Linked model elements. |
| LinkedMeasures | list | Linked countermeasures. |
| LinkedScenarios | list | Linked Attack Scenarios |
| Name | scalar | Display name of the entry. |
| Number | scalar | Number shown for the entry. |
| PreConditions | list | Preconditions of the test case. |
| Status | scalar | Status |
| Steps | list | Execution steps of the test case. |
| Summary | list | Summary/result entries of the test case. |
| TestData | list | Input and expected test data. |
| Version | scalar | Version of the test case. |
threatSources
- Description: All threat sources.
- Aliases: threatActors
| Name | Kind | Description |
|---|---|---|
| Capabilities | list | Capabilities assigned to the threat source. |
| Description | scalar | Description text of the entry. |
| Hyperlinks | scalar | Referenced hyperlinks of the entry. |
| Identifier | scalar | Unique reference identifier of the entry. |
| Likelihood | scalar | Likelihood value of the threat source. |
| Motive | list | Motivation characteristics of the threat source. |
| Name | scalar | Display name of the entry. |
| Number | scalar | Number shown for the entry. |
useCaseDiagrams
- Description: All use case diagrams.
| Name | Kind | Description |
|---|---|---|
| attackScenarios | list | Attack Scenarios |
| AttackScenarios | list | Attack Scenarios |
| countermeasures | list | Countermeasures |
| Countermeasures | list | Countermeasures |
| DiagramType | scalar | Type of the diagram entry. |
| Image | scalar | Rendered image payload of the diagram. |
| Name | scalar | Display name of the entry. |
| Path | scalar | Source path or location label of the diagram. |
Entity Properties
| Entity | Property | Kind |
|---|---|---|
| Project | Description | scalar |
| Project | Devices | list |
| Project | Hyperlinks | scalar |
| Project | Image | scalar |
| Project | MobileApps | list |
| Project | Modules | list |
| Project | Name | scalar |
| Project | Number | scalar |
| Project | Participants | list |
| Project | ProjectName | scalar |
| Project | ProjectVersion | scalar |
| Project | SystemsUnderConsideration | scalar |
| Project | SystemUnderConsideration | scalar |
| Project | UserVersions | list |
| Project | Workshops | list |
| Assumptions | AssumptionCategories | scalar |
| Assumptions | Automations | scalar |
| Assumptions | Categories | scalar |
| Assumptions | Definitions | scalar |
| Assumptions | Description | scalar |
| Assumptions | Hyperlinks | scalar |
| Assumptions | Identifier | scalar |
| Assumptions | Name | scalar |
| Assumptions | Number | scalar |
| Assumptions | Responsible | scalar |
| Assumptions | Validated | scalar |
| Assets | Description | scalar |
| Assets | Hyperlinks | scalar |
| Assets | Identifier | scalar |
| Assets | ImpactCats | scalar |
| Assets | ImpactPerProtectionGoal | scalar |
| Assets | Name | scalar |
| Assets | Number | scalar |
| Assets | Sensitivity | scalar |
| Assets | Type | scalar |
| AttackScenario | AffectedAssetObjects | scalar |
| AttackScenario | AttackVector | scalar |
| AttackScenario | CAPECID | scalar |
| AttackScenario | CAPECLink | scalar |
| AttackScenario | Countermeasures | scalar |
| AttackScenario | CvssNotes31 | scalar |
| AttackScenario | CvssNotes40 | scalar |
| AttackScenario | CvssScore31 | scalar |
| AttackScenario | CvssScore40 | scalar |
| AttackScenario | CvssVector31 | scalar |
| AttackScenario | CvssVector40 | scalar |
| AttackScenario | CWEID | scalar |
| AttackScenario | CWELink | scalar |
| AttackScenario | Description | scalar |
| AttackScenario | Diagram | scalar |
| AttackScenario | EMB3DID | scalar |
| AttackScenario | EMB3DLink | scalar |
| AttackScenario | Hyperlinks | scalar |
| AttackScenario | Identifier | scalar |
| AttackScenario | LinkedRequirements | scalar |
| AttackScenario | LinkedScenarios | scalar |
| AttackScenario | LinkedTestCases | scalar |
| AttackScenario | MyTags | scalar |
| AttackScenario | Name | scalar |
| AttackScenario | Number | scalar |
| AttackScenario | OwaspScore | scalar |
| AttackScenario | OwaspVector | scalar |
| AttackScenario | ProtectionGoals | scalar |
| AttackScenario | RemainingCvssNotes31 | scalar |
| AttackScenario | RemainingCvssNotes40 | scalar |
| AttackScenario | RemainingCvssScore31 | scalar |
| AttackScenario | RemainingCvssScore40 | scalar |
| AttackScenario | RemainingCvssVector31 | scalar |
| AttackScenario | RemainingCvssVector40 | scalar |
| AttackScenario | RemainingOwaspScore | scalar |
| AttackScenario | RemainingOwaspVector | scalar |
| AttackScenario | RiskStrategy | scalar |
| AttackScenario | RiskStrategyReason | scalar |
| AttackScenario | RNotesCVSS | scalar |
| AttackScenario | RNotesCVSS40 | scalar |
| AttackScenario | RNotesCVSSdefault | scalar |
| AttackScenario | RRNotesCVSS | scalar |
| AttackScenario | RRNotesCVSS40 | scalar |
| AttackScenario | RRNotesCVSSdefault | scalar |
| AttackScenario | RRScoreCVSS | scalar |
| AttackScenario | RRScoreCVSS40 | scalar |
| AttackScenario | RRScoreCVSSdefault | scalar |
| AttackScenario | RRScoreOwaspRR | scalar |
| AttackScenario | RRVectorCVSS | scalar |
| AttackScenario | RRVectorCVSS40 | scalar |
| AttackScenario | RRVectorCVSSdefault | scalar |
| AttackScenario | RRVectorOwaspRR | scalar |
| AttackScenario | RScoreCVSS | scalar |
| AttackScenario | RScoreCVSS40 | scalar |
| AttackScenario | RScoreCVSSdefault | scalar |
| AttackScenario | RScoreOwaspRR | scalar |
| AttackScenario | RVectorCVSS | scalar |
| AttackScenario | RVectorCVSS40 | scalar |
| AttackScenario | RVectorCVSSdefault | scalar |
| AttackScenario | RVectorOwaspRR | scalar |
| AttackScenario | Status | scalar |
| AttackScenario | SystemThreats | scalar |
| AttackScenario | Target | scalar |
| AttackScenario | Targets | scalar |
| AttackScenario | TargetType | scalar |
| AttackScenario | ThreatCategories | scalar |
| AttackScenario | ThreatSources | scalar |
| AttackScenario | ThreatState | scalar |
| AttackScenario | TreatmentState | scalar |
| AttackScenario | TreatmentStatus | scalar |
| Countermeasure | AttackScenarios | list |
| Countermeasure | AttackVectors | scalar |
| Countermeasure | Control | scalar |
| Countermeasure | Description | scalar |
| Countermeasure | Diagram | scalar |
| Countermeasure | EMB3DIDs | scalar |
| Countermeasure | Hyperlinks | scalar |
| Countermeasure | Identifier | scalar |
| Countermeasure | LinkedRequirements | scalar |
| Countermeasure | LinkedTestCases | scalar |
| Countermeasure | MaxRisk | scalar |
| Countermeasure | MitigationProcess | scalar |
| Countermeasure | MitigationState | scalar |
| Countermeasure | MyTags | scalar |
| Countermeasure | Name | scalar |
| Countermeasure | Number | scalar |
| Countermeasure | Status | scalar |
| Countermeasure | Targets | scalar |
| MitigationProcess | AttackScenarios | scalar |
| MitigationProcess | Countermeasures | scalar |
| MitigationProcess | Description | scalar |
| MitigationProcess | Hyperlinks | scalar |
| MitigationProcess | Identifier | scalar |
| MitigationProcess | MaxRisk | scalar |
| MitigationProcess | MitigationProcessState | scalar |
| MitigationProcess | Name | scalar |
| MitigationProcess | Notes | list |
| MitigationProcess | Number | scalar |
| MitigationProcess | Progress | scalar |
| MitigationProcess | Status | scalar |
| MitigationProcess | Tasks | list |
| SystemThreat | AffectedAssetObjects | scalar |
| SystemThreat | attackScenarios | list |
| SystemThreat | AttackScenarios | list |
| SystemThreat | Description | scalar |
| SystemThreat | Hyperlinks | scalar |
| SystemThreat | Identifier | scalar |
| SystemThreat | Impact | scalar |
| SystemThreat | ImpactCats | scalar |
| SystemThreat | ImpactPerProtectionGoal | scalar |
| SystemThreat | MaxRisk | scalar |
| SystemThreat | Name | scalar |
| SystemThreat | Number | scalar |
| SystemThreat | ThreatCategory | scalar |
| ThreatSources | Capabilities | list |
| ThreatSources | Description | scalar |
| ThreatSources | Hyperlinks | scalar |
| ThreatSources | Identifier | scalar |
| ThreatSources | Likelihood | scalar |
| ThreatSources | Motive | list |
| ThreatSources | Name | scalar |
| ThreatSources | Number | scalar |
| TestCase | Description | scalar |
| TestCase | Hyperlinks | scalar |
| TestCase | Identifier | scalar |
| TestCase | Images | list |
| TestCase | LinkedElements | list |
| TestCase | LinkedMeasures | list |
| TestCase | LinkedScenarios | list |
| TestCase | Name | scalar |
| TestCase | Number | scalar |
| TestCase | PreConditions | list |
| TestCase | Status | scalar |
| TestCase | Steps | list |
| TestCase | Summary | list |
| TestCase | TestData | list |
| TestCase | Version | scalar |
| Checklist | Justification | scalar |
| Checklist | Level1 | scalar |
| Checklist | Level2 | scalar |
| Checklist | Level3 | scalar |
| Checklist | Level4 | scalar |
| Checklist | Level5 | scalar |
| Checklist | LinkedMeasures | list |
| Checklist | LinkedScenarios | list |
| Checklist | Name | scalar |
| Checklist | Notes | scalar |
| Checklist | Prefix | scalar |
| Checklist | PrefixPath | scalar |
| Diagram | attackScenarios | list |
| Diagram | AttackScenarios | list |
| Diagram | countermeasures | list |
| Diagram | Countermeasures | list |
| Diagram | DiagramType | scalar |
| Diagram | Image | scalar |
| Diagram | Name | scalar |
| Diagram | Path | scalar |
Dynamic Property Patterns
These patterns are configuration dependent and not expanded with project-specific IDs in this generic reference.
| Entity | Pattern |
|---|---|
| Assets | PG{protectionGoalID} |
| Assets | IC{impactCategoryID} |
| AttackScenario | R{metricID} |
| AttackScenario | NR{metricID} |
| AttackScenario | RR{metricID} |
| AttackScenario | NRR{metricID} |
Dynamic Root Variable Patterns
These dynamic lookups are available on analysis scope root variables and aliases.
| Variable | Pattern | Result |
|---|---|---|
| characterizationScope | [" |
object with Name and Value |
| objectivesImpact | [" |
object with Name and Value |
| charScope | [" |
object with Name and Value |
| objImpact | [" |
object with Name and Value |