STRIDE: Spoofing, Tampering, Repudiation, Information Disclosure, Denial of Service, Elevation of Privilege in Cybersecurity

Frameworks
ByDecipherU Editorial
How is it pronounced?
stride/straɪd/

One word, like the running motion.

STRIDE stands for Spoofing, Tampering, Repudiation, Information Disclosure, Denial of Service, Elevation of Privilege. STRIDE is Microsoft's threat modeling methodology that categorizes threats into six types. Each category maps to a specific security property: authentication, integrity, non-repudiation, confidentiality, availability, and authorization.

How STRIDE Is Used in Cybersecurity

Security architects apply STRIDE during design reviews to identify threats against new systems and applications. Penetration testers use STRIDE categories to structure their attack narratives and findings reports. Threat modeling with STRIDE is a standard practice in secure software development lifecycles.

Read the full glossary entry: STRIDE in Cybersecurity

Cybersecurity Roles That Work with STRIDE

Related Cybersecurity Acronyms

Frequently asked questions

What does STRIDE stand for?

STRIDE stands for Spoofing, Tampering, Repudiation, Information Disclosure, Denial of Service, Elevation of Privilege. STRIDE is Microsoft's threat modeling methodology that categorizes threats into six types. Each category maps to a specific security property: authentication, integrity, non-repudiation, confidentiality, availability, and authorization.

What is STRIDE used for in cybersecurity?

Security architects apply STRIDE during design reviews to identify threats against new systems and applications. Penetration testers use STRIDE categories to structure their attack narratives and findings reports. Threat modeling with STRIDE is a standard practice in secure software development lifecycles.

Last verified: April 2026?Report an inaccuracy