update lists

This commit is contained in:
2025-07-18 22:22:32 +02:00
parent 55bed3b4a1
commit 5916c5c074
3078 changed files with 331679 additions and 357255 deletions

View File

@@ -1,4 +1,4 @@
 Awesome Security Card Games !Awesome (https://awesome.re/badge.svg) (https://github.com/sindresorhus/awesome)
 Awesome Security Card Games !Awesome (https://awesome.re/badge.svg) (https://github.com/sindresorhus/awesome)
▐ A curated list of security card games (which are sometimes known as tabletop exercises).
@@ -15,8 +15,9 @@
Application Security
- Cornucopia (https://www.owasp.org/index.php/OWASP_Cornucopia) - A card game based on OWASP's Top 10 (authentication, data Validation etc.). The card deck (https://www.owasp.org/images/7/71/Owasp-cornucopia-ecommerce_website.pdf) is 
available as PDF from OWASP.
- Cornucopia (https://cornucopia.owasp.org) - OWASP® Cornucopia is a threat modeling tool in the form of a card game to assist software development teams identify security requirements in Agile, conventional and formal development processes. It's
based on OWASP's Top 10, ASVS/MASVS/MASTG, CAPEC and SAFECode. The card decks (https://cornucopia.owasp.org/webshop)) are available both as a Website version and a Mobile version as physical decks that can be bought online or in a digital format 
at copi.owasp.org (https://copi.owasp.org).
Cryptography
@@ -25,8 +26,7 @@
Data Privacy
- Know your risks (https://aca.edu.au/resources/cyber-sharing-cards/) - Learn what information is safe to share online and understand the risks. Learn about whether to share, not share or be cautious with different pieces of 
information.
- Know your risks (https://aca.edu.au/resources/cyber-sharing-cards/) - Learn what information is safe to share online and understand the risks. Learn about whether to share, not share or be cautious with different pieces of information.
Incident Response
@@ -35,20 +35,21 @@
Threat Modeling
- Elevation of Privilege (EOP) by Microsoft (https://web.archive.org/web/20150312215303/http://www.microsoft.com/security/sdl/adopt/eop.aspx) - A card game based on Microsoft's threat modeling framework "STRIDE" (Spoofing, Tampering 
etc.). The card deck (https://www.microsoft.com/en-us/download/details.aspx?id=20303) is available as PDF from Microsoft. Adam Shostack, the author of EoP has also a git repo (https://github.com/adamshostack/eop/) for EoP.
- Security Cards (http://securitycards.cs.washington.edu/index.html) - A card game encouraging to think broadly and creatively about computer security threats. Four dimensions are covered: Human Impact, Adversary's Motivations, 
Adversary's Resources, Adversary's Methods.
- Elevation of Privilege (EOP) by Microsoft (https://web.archive.org/web/20150312215303/http://www.microsoft.com/security/sdl/adopt/eop.aspx) - A card game based on Microsoft's threat modeling framework "STRIDE" (Spoofing, Tampering etc.). The 
card deck (https://www.microsoft.com/en-us/download/details.aspx?id=20303) is available as PDF from Microsoft. Adam Shostack, the author of EoP has also a git repo (https://github.com/adamshostack/eop/) for EoP.
- Security Cards (http://securitycards.cs.washington.edu/index.html) - A card game encouraging to think broadly and creatively about computer security threats. Four dimensions are covered: Human Impact, Adversary's Motivations, Adversary's 
Resources, Adversary's Methods.
- Cumulus (https://github.com/TNG/cumulus) - A threat modeling card game for the clouds which helps you find threats to your DevOps or cloud project and teaches developers a security oriented mindset.
Various Resources
- Tabletop Security Games & Cards (https://adam.shostack.org/games.html) - List of security card games created and maintained by Adam Shostack.
- Tabletop Simulations to Improve Your Information Security Program (https://redcanary.com/blog/using-tabletop-simulations-to-improve-information-security/) - Red Canary's write-up about tabletop exercises for information security 
programs.
- Game On: Tabletop Games to Teach Cyber and Information Security Concepts (https://www.linkedin.com/pulse/game-tabletop-games-teach-cyber-information-security-mike-mcgannon) - List of tabletop games to teach cyber and information 
security concepts.
- Tabletop Simulations to Improve Your Information Security Program (https://redcanary.com/blog/using-tabletop-simulations-to-improve-information-security/) - Red Canary's write-up about tabletop exercises for information security programs.
- Game On: Tabletop Games to Teach Cyber and Information Security Concepts (https://www.linkedin.com/pulse/game-tabletop-games-teach-cyber-information-security-mike-mcgannon) - List of tabletop games to teach cyber and information security 
concepts.
Contributing
Contributions welcome! Read the contribution guidelines (CONTRIBUTING.md) first.
securitycardgames Github: https://github.com/Karneades/awesome-security-card-games