Threat modeling for everyone everywhere
Uncover the security flaws in your software's before the bad guys do it for you by playing the game! Get your team together on a call or in a room and use OWASP Cornucopia Web & Mobile card decks to guide your threat modelling.
Alice can utilize the application to attack users' systems and data
Mwengu's actions cannot be investigated because there is not an adequate accurately time-stamped record of security events, or there is not a full audit trail, or these can be altered or deleted by Mwengu, or there is no centralized logging service
Romain can read and modify unencrypted data in memory or in transit (e.g. cryptographic secrets, credentials, session identifiers, personal and commercially-sensitive data), in use or in communications within the application, or between the application and users, or between the application and external systems
Chad can access resources (including services, processes, AJAX, video, images, documents, temporary files, session data, system properties, configuration data, registry settings, logs) he should not be able to due to missing authorization, or due to excessive privileges (e.g. not using the principle of least privilege)
Alison can set session identification cookies or use tokens for another web application because the domain, path, (or in the case of tokens) audience are not restricted sufficiently
Robert can input malicious data because the allowed protocol format is not being checked, or duplicates are accepted, or the structure is not being verified, or the individual data elements are not being sanitized, or preferably validated for format, type, range, size, length and a whitelist of allowed characters or formats
James can undertake authentication functions without the real user ever being aware this has occurred (e.g. attempt to log in, log in with stolen credentials, reset the password)
Introduction
The idea behind Cornucopia is to help development teams, especially those using Agile methodologies, to identify application security requirements and develop security-based user stories.
OWASP Cornucopia is an easy way to introduce the practice of threat modeling in a software development team. Playing the card game encourages the development team to actively think about the kind of threats that can emerge when creating software. This empowers teams to independently secure their applications while building them. Doing so embraces the shift-left strategy, where security becomes an integrated part of the development cycle.
➔ Read moreHow to start
To start using Cornucopia:
- Either obtain or buy a pre-printed deck of cards;
- Or: Download the free Adobe Illustrator files and get them professionally printed (see: printing instructions);
- Or: Play the game online at copi.owasp.org.
- Identify an application, module or component to assess.
- Invite business owners, architects, developers, testers along for a card game.
- Get those infosec folk to provide chocolate, pizza, beer, flowers or all four as prizes.
- Select a portion of the deck to start with.
- Play the game to discuss & document security requirements (and to win rounds).
- Remember, to have fun!

Open source
There are a large number of source design files for the cards themselves in various languages and formats. These design files together with the source code to generate the Word document, PDFs and InDesign files for printing are maintained in our Github repository.
One of the main advantages of the OWASP Cornucopia card game being open source is that it allows anyone to access and use the game without any licensing fees or restrictions. This encourages widespread adoption and makes it easier for teams to integrate the game into their security practices. Additionally, being open source means that the game is transparent and customizable. Teams can modify the game to suit their specific needs and address the security threats that are most relevant to their applications. They can also contribute back to the game's development by submitting new cards or improvements. Furthermore, open source software tends to have a large and active community of developers who contribute to the codebase and offer support. This can lead to faster bug fixes and updates, ensuring that the game remains relevant and effective in identifying security threats.
View source on Github ➔
Sponsors:
We thank our donors for providing the funds to support us on our project activities.
OWASP Cornucopia & the OWASP Foundation is very grateful for the support by the individuals and organizations listed. However please note, the OWASP Foundation is strictly vendor neutral and does not endorse any of its supporters. Donations do not influence the content of OWASP Cornucopia in any way.
Read more about the benefits of becoming a Gold, Silver, Bronze, or Supporter sponsor.
Enhance Your Brand’s Commitment to Security by Sponsoring OWASP Cornucopia ➔