model attacker goals and paths against a system, covering entry points and trust levels, stride categorization, attack trees and chained paths, abuse and misuse cases, business logic and fraud abuse, adversary technique references where a source names them, mapping each threat to a named mitigating control with its enforcement point, and candidate accepted risks. use for design-stage threat models, what-could-go-wrong analysis on a change, abuse case definition, and building the threat basis for detection and test coverage.