OWASP Cornucopia is a card game designed to integrate threat modeling into the agile development process. It is an open-source project on Github that is part of OWASP, The Open Worldwide Application Security Project®. Visit the project page for more information.
Created by Colin Watson.
OWASP Cornucopia is open source and can be downloaded free of charge from the OWASP Website.
OWASP Cornucopia is free to use.
It is licensed under the Creative Commons Attribution-ShareAlike 3.0 license, so you can copy, distribute and transmit the work, and you can adapt it, and use it commercially, but all provided that you attribute the work and if you alter, transform, or build upon this work, you may distribute the resulting work only under the same or similar license to this one.
OWASP and the OWASP logo are trademarks of the OWASP Foundation
At DotNET lab, we decided to add additional information and examples to the cards by adding a QR code to them. This site provides the information behind the QR code, which we try to update regularly!
This site is maintained by Jef Meijvis. Please do get in touch if you have any questions, remarks or suggestions! Also get in touch if you would like to have your own branded version.