ArgusTM V2 / Public proof of concept
A team of agents drafts the threat model. You make the call.
Give ArgusTM a system description, RFC or architecture document. Specialist agents apply STRIDE, PASTA-inspired analysis and attack trees, challenge candidate findings, and build a traceable draft for your review.
Watch the walkthrough
A desktop run and review workspace. The findings shown are analysis outputs, not verified vulnerabilities.
- Status
- Available
- Version
- V2 proof of concept
- Licence
- PolyForm Perimeter 1.0.1
- Repository
- GitHub / philocyber
The problem
Ask a single model to threat-model a system and you get one pass, one perspective and no evidence trail — findings nobody can verify, prioritize or defend in front of a reviewer. What makes a threat model credible is the triangulation, the challenge and the traceability, and that is exactly the part a chat window does not do.
Who it is for
Security and AppSec teams reviewing architectures, engineers who need a defensible threat model before production, and reviewers who want to disagree with a finding instead of re-deriving it.
From architecture to a reviewable draft
Start with a system description or RFC. The tool maps architecture and trust boundaries, compares threat scenarios through specialist analyses and Red / Blue challenge, then prepares findings for your decision. Try a synthetic example first; review every result before acting on it.
What it does
Three methodologies, triangulated
STRIDE, PASTA and attack-tree analysts run as separate specialist agents — in hybrid, parallel or cascade mode — instead of one model's single pass.
Adversarial review built in
A Red/Blue team debate challenges every candidate threat, then a DREAD validator calibrates scores against the official grid.
Evidence-gated priorities
High and critical priorities demand traceable evidence: components, trust boundaries, endpoints and security configs.
Grounded in a real corpus
Optional retrieval from sources you approve. Retrieved passages keep their provenance and still need human review.
Local-first and offline-capable
Every project is a portable folder with its own SQLite database. Runs fully offline with Ollama, or plugs into Gemini, Kimi or AWS Bedrock.
It learns from your reviews
Confirm/Reject decisions feed back as few-shot examples on the next run, and run diffs show what changed between analyses of the same system.
How it works
- 01/08Architecture Parser
Extracts components, data flows and trust boundaries from your RFC, and draws the DFD and architecture diagrams.
- 02/08STRIDE Analyst
Maps threat classes against each element of the system.
- 03/08PASTA Analyst
Runs the seven-stage risk analysis over the attack surface.
- 04/08Attack Tree Analyst
Traces concrete attack paths instead of generic checklist items.
- 05/08Pre-dedup
Merges duplicate findings with embeddings and a confidence filter, keeping each methodology's fields.
- 06/08Red/Blue Debate
Red argues, Blue answers, a judge can rule — rounds stop early on convergence.
- 07/08Threat Synthesizer
Unifies everything into one register: unique IDs, OWASP mapping, NIST/CIS control references, evidence sources.
- 08/08DREAD Validator
Calibrates scores against the official DREAD grid and rewrites each threat from the adversary's perspective.
Interface
What it looks like in practice
Screenshots from ArgusTM, showing the current proof-of-concept interface and a synthetic example.

01/02
Follow the live analysis
Watch architecture mapping, specialist analyses, challenge and synthesis progress through the pipeline.
Use it in your own environment
Individuals and companies may run and adapt ArgusTM V2 for their own work, including private internal use. Source and setup instructions are free to access. The PolyForm Perimeter 1.0.1 license restricts offering a competing product or service to others, including a repackaged SaaS, whether paid or free. Read the license for the controlling terms.
Read the license and usage termsHelp make the findings better
Found a weak evidence link, an unclear scenario, a setup problem or an idea for the review flow? Open an issue with a small reproducible example. Use synthetic or public material only; keep your organization's architecture and credentials private.
Try it and tell us what breaks
Put the draft under human review.
Clone the repository, follow the local setup guide and run a synthetic example. Challenge the findings, then share reproducible feedback in an issue.
Open the repositoryContinue with the material that is public today.
The field guide documents the method, and the assessment offers a practical place to identify what to study next.
Back to the AI Security Lab

