Skip to content
PhiloCyber logo

ArgusTM V2 / Public proof of concept

A team of agents drafts the threat model. You make the call.

Give ArgusTM a system description, RFC or architecture document. Specialist agents apply STRIDE, PASTA-inspired analysis and attack trees, challenge candidate findings, and build a traceable draft for your review.

Watch the walkthrough

A desktop run and review workspace. The findings shown are analysis outputs, not verified vulnerabilities.

Status
Available
Version
V2 proof of concept

The problem

Ask a single model to threat-model a system and you get one pass, one perspective and no evidence trail — findings nobody can verify, prioritize or defend in front of a reviewer. What makes a threat model credible is the triangulation, the challenge and the traceability, and that is exactly the part a chat window does not do.

Who it is for

Security and AppSec teams reviewing architectures, engineers who need a defensible threat model before production, and reviewers who want to disagree with a finding instead of re-deriving it.

From architecture to a reviewable draft

Start with a system description or RFC. The tool maps architecture and trust boundaries, compares threat scenarios through specialist analyses and Red / Blue challenge, then prepares findings for your decision. Try a synthetic example first; review every result before acting on it.

What it does

Three methodologies, triangulated

STRIDE, PASTA and attack-tree analysts run as separate specialist agents — in hybrid, parallel or cascade mode — instead of one model's single pass.

Adversarial review built in

A Red/Blue team debate challenges every candidate threat, then a DREAD validator calibrates scores against the official grid.

Evidence-gated priorities

High and critical priorities demand traceable evidence: components, trust boundaries, endpoints and security configs.

Grounded in a real corpus

Optional retrieval from sources you approve. Retrieved passages keep their provenance and still need human review.

Local-first and offline-capable

Every project is a portable folder with its own SQLite database. Runs fully offline with Ollama, or plugs into Gemini, Kimi or AWS Bedrock.

It learns from your reviews

Confirm/Reject decisions feed back as few-shot examples on the next run, and run diffs show what changed between analyses of the same system.

How it works

  1. 01/08Architecture Parser

    Extracts components, data flows and trust boundaries from your RFC, and draws the DFD and architecture diagrams.

  2. 02/08STRIDE Analyst

    Maps threat classes against each element of the system.

  3. 03/08PASTA Analyst

    Runs the seven-stage risk analysis over the attack surface.

  4. 04/08Attack Tree Analyst

    Traces concrete attack paths instead of generic checklist items.

  5. 05/08Pre-dedup

    Merges duplicate findings with embeddings and a confidence filter, keeping each methodology's fields.

  6. 06/08Red/Blue Debate

    Red argues, Blue answers, a judge can rule — rounds stop early on convergence.

  7. 07/08Threat Synthesizer

    Unifies everything into one register: unique IDs, OWASP mapping, NIST/CIS control references, evidence sources.

  8. 08/08DREAD Validator

    Calibrates scores against the official DREAD grid and rewrites each threat from the adversary's perspective.

Interface

Screenshots from ArgusTM, showing the current proof-of-concept interface and a synthetic example.

A team of agents drafts the threat model. You make the call. — Follow the live analysis

01/02

Follow the live analysis

Watch architecture mapping, specialist analyses, challenge and synthesis progress through the pipeline.

Use it in your own environment

Individuals and companies may run and adapt ArgusTM V2 for their own work, including private internal use. Source and setup instructions are free to access. The PolyForm Perimeter 1.0.1 license restricts offering a competing product or service to others, including a repackaged SaaS, whether paid or free. Read the license for the controlling terms.

Read the license and usage terms

Help make the findings better

Found a weak evidence link, an unclear scenario, a setup problem or an idea for the review flow? Open an issue with a small reproducible example. Use synthetic or public material only; keep your organization's architecture and credentials private.

Try it and tell us what breaks

Put the draft under human review.

Clone the repository, follow the local setup guide and run a synthetic example. Challenge the findings, then share reproducible feedback in an issue.

Open the repository

Continue with the material that is public today.

The field guide documents the method, and the assessment offers a practical place to identify what to study next.

Back to the AI Security Lab
Open the field guide
ArgusTM | PhiloCyber