DEV Community

Cover image for OWASP Cornucopia v3 with EoP and PHANTOM-B
Johan Sydseter for OWASP® Foundation

Posted on • Originally published at cornucopia.owasp.org

OWASP Cornucopia v3 with EoP and PHANTOM-B

We’re thrilled to bring you OWASP Cornucopia v3.4 with an update that expands how we identify threats, whether you're mapping out traditional applications or diving headfirst into the latest AI architectures.


Elevation of Privilege (EoP)

One of the exciting updates in this release is the addition of the Elevation of Privilege (EoP) deck to the Cornucopia Help Pages. The new help pages are directly linked from our online game engine Copi when you play EoP at copi.owasp.org

EoP

We Need Your Help!

While the game is live, we are actively looking for community contributors to help us with the help pages for each of the EoP cards. Specifically, we need security minds to help players better answer:

  • What can go wrong?
  • What are we going to do about it?

If you have experience with EoP or want to flex your threat mitigation muscles, we would love your pull requests to help guide players!

Why are we doing this? Well, first off, it is to give players the option to visit the EoP help pages while they are playing EoP at copi.owasp.org!

EoP at copi.owasp.org

When playing EoP at copi.owasp.org, you will now be able to click the «Need more info» links on each card, which will take you to the help pages, and we are looking for your expertise to fill them out.

Thanking Our GSoC Contributors

I want to take a moment to extend a massive thank you to our Google Summer of Code (GSoC) student, Ayman Algamal. Ayman has taken on adding the EoP game to our card browser for OWASP Cornucopia. At a high level, this project aims to solve the current roadblock where OWASP Threat Dragon lacks the ability to integrate EoP into their EoP games threat modelling diagrams. By adding a fully browsable EoP deck and exposing the cards through the existing API, Ayman's work will cleanly unblock this integration. We hope this will help development teams to more easily use EoP during their threat modelling sessions. Read more about how further down!

AI Threat Modelling with PHANTOM-B

PHANTOM-B, July, 2026, by Adam Shostack

As we look at the shifting landscape of application security, Large Language Models (LLMs) and Agentic AI are introducing entirely new threat vectors. To help you tackle these, the Cornucopia Companion suits for Large Language Models and Agentic AI have been upgraded.

We have officially added PHANTOM-B mapping to each of these cards. If you check the help pages for the LLM and Agentic AI cards, you will now find detailed explanations for these mappings to help your team get familiar with AI Threat Modelling natively in your sessions.

What is PHANTOM-B?

If you haven't read Adam Shostack's recent post on Why PHANTOM-B?, PHANTOM-B is a tool designed to structure how you answer the question: "What can go wrong?» (with the LLM parts of the system).

Created by Adam Shostack and the Shostack + Associates team—and validated alongside hyperscalers and global financial institutions—it serves as a STRIDE-analogous mnemonic specifically engineered for LLMs. While vulnerability lists like the OWASP LLM Top 10 are fantastic for general awareness, they don't explicitly tell you how your specific architecture will fail.

PHANTOM-B provides a repeatable, lightweight threat elicitation tool that focuses strictly on what engineering teams can actually control and influence, scaling down complex generative AI behaviours into an actionable map.

Seats are filling up fast for Shostack + Associates Threat Modelling Intensive with Complete AI at this year’s Black Hat conference. If you are interested in knowing more about AI Threat Modelling and are in the vicinity, you should not forget to sign up.

Registrations for their course is apparently still open! https://blackhat.com/us-26/training/schedule/index.html#adam-shostacks-threat-modeling-intensive-with-complete-ai-51473?trk=public_post_comment-text

Cornucopia, now 100% synced with AISVS v1.0

In case you missed it, AISVS - OWASP Artificial Intelligence Security Verification Standard was recently released as version 1.0, and we have made sure OWASP Cornucopia is correctly mapped to AISVS This, so that after you have figured out what can go wrong with LLM and Agentic during the threat modeling sessions, we can help you answer the question: «What are we going to do about it?»

A special thanks to Mayur Agnihotri for adding AISVS v1 “High-Impact Action Approval and Irreversibility Controls” to the Agentic AI cards and to Adarsh Kumar for continuing pushing out bug fixes. You both rock!

Smarter, Smoother Game Sessions

Finally, we know that scheduling a full threat modelling session with your entire team isn't always easy, and sometimes network connections and web browsers fail.

Save Player state

To improve the player experience, we have upgraded game sessions by saving the session state server-side. In addition to stability, we have introduced the concept of sharing your card hand. If you run out of time or have an emergency, you can simply hand off your cards so another team member can seamlessly take over your spot.

Share you Cornucopia hand

We can’t wait for you to try out 3.4.0. Grab your team, deal your hands, and let’s make threat modelling fun again!

Threat Dragon and EoP Games

Threat Dragon and EoP Games

When choosing a tool for publishing our threat model, we chose OWASP Threat Dragon. OWASP Threat Dragon is a free, open-source, cross-platform threat modelling application. It is used to create threat modelling diagrams and list threats for elements within the diagrams. Mike Goodwin created Threat Dragon as an open-source community project that provides an intuitive, accessible way to model threats.

OWASP Threat Dragon recently released this possibility in v2.6. This was just the start of integration between the two projects. In v2.7 of OWASP Threat Dragon, we will make both the OWASP Cornucopia Companion Edition and Elevation of Privilege available from Threat Dragon!

How to choose to create a OWASP Cornucopia threat model

It's now possible to create your OWASP Cornucopia Threat Model directly in OWASP Threat Dragon. When creating a new diagram for your threat model, simply choose to create an EoP Games diagram. We chose to call the diagram EoP Games for two reasons. One, OWASP Cornucopia is derived from the Elevation of Privilege game created by Adam Shostack. Second, we don't want to stop with OWASP Cornucopia. We also want to add other EoP games, such as the original Elevation of Privilege game.

Create a OWASP Cornucopia threat

Once you have created an EoP Games diagram, you can add OWASP Cornucopia threats to your threat model. The specific threat you add will get a link reference to the OWASP Cornucopia website, where you will find guidance on threat modelling and STRIDE, which will help you in identifying what can go wrong and what to do about it. You can also find a complete mapping to OWASP ASVS, OWASP Developer Guide, and all relevant CAPECs.

OWASP Corncupia Website

Final words

OWASP Cornucopia welcomes any input or improvements you might be willing to share with us. For anyone wanting to share their opinion, please don't hesitate to visit our repository, share your feedback, and, if appropriate, give us a star⭐️.


OWASP is a non-profit foundation that envisions a world with no more insecure software. Our mission is to be the global open community that powers secure software through education, tools, and collaboration. We maintain hundreds of open source projects, run industry-leading educational and training conferences, and meet through over 340 chapters worldwide.

Top comments (0)