About
OWASP Cornucopia is a mechanism in the form of a card game to assist software development teams in identifying security requirements in Agile, conventional and formal development processes. It is language-, platform-, and technology-agnostic.
If you have questions concerning OWASP Cornucopia, please search for it first in our Q & A section.
If you have other questions, suggestions or ideas, please feel free to discuss them on our email list or submit them to our list of issues in our repository. If you feel like and have the opportunity to help, do not hesitate to get in touch with us.
Introduction
The idea behind Cornucopia is to help development teams, especially those using Agile methodologies, identify application security requirements and develop security-based user stories. Although the concept had been waiting for enough time to progress, the final motivation came when SAFECode published its Practical Security Stories and Security Tasks for Agile Development Environments in July 2012.
Cornucopia was created and first used for developer training in August 2012.
The Microsoft SDL team had already published its super Elevation of Privilege: The Threat Modelling Game (EoP), but that did not seem to address the most appropriate kind of issues that web application development teams mostly have to address.
EoP is a great concept and game strategy and was published under a Creative Commons Attribution License.
Cornucopia is based on the concepts and game ideas in EoP, but those have been modified to be more relevant to the types of issues website, app, and mobile app developers encounter.
It attempts to introduce threat-modelling ideas into development teams that use Agile methodologies or are more focused on web application weaknesses than other types of software vulnerabilities or are not familiar with STRIDE and DREAD.
How to start
To start using Cornucopia:
- Either obtain or buy a pre-printed deck of cards;
- Or: Download the free Adobe Illustrator files and get them professionally printed (see: printing instructions;
- Or: Play the game online at copi.owasp.org.
- Identify an application, module or component to assess.
- Invite business owners, architects, developers, and testers along for a card game.
- Get those infosec folk to provide chocolate, pizza, beer, flowers or all four as prizes.
- Select a portion of the deck to start with.
- Play the game to discuss & document security requirements (and to win rounds).
- Remember to have fun!
Mappings
The other driver for Cornucopia was to link the attacks with requirements and verification techniques. An initial aim had been to reference CWE™ weakness IDs, but these proved too numerous, and instead it was decided to map each card to CAPEC™ Software attack pattern IDs, which themselves are mapped to CWEs, so the desired result is achieved.
Each Website App Edition card is also mapped to the 36 primary security stories in the SAFECode document, as well as to the OWASP Developer Guide Web Application Checklist v2, ASVS v4.0.3 and AppSensor (application attack detection and response) to help teams create their own security-related stories for use in Agile processes.
Likewise, each Mobile App Edition is mapped to CAPEC™ and the SAFECode stories, but instead of SCP, ASVS, and AppSensor, each card is mapped to OWASP's Mobile Application Security Verification Standard (MASVS) v2.0 and Mobile Application Security Testing Guide (MASTG) v2.0.
There is also the OWASP Cornucopia Companion Edition, which extends the previous two editions with 6 additional suites. These 6 companion suites cover new Agentic AI (AAI), Automated Threats (BOT), Cloud (CLD), Frontend (FRE), Large Language Models (LLM), and DevOps (DVO). These suites are mapped to various standards, maturity models, OWASP Top 10s, guides, lists, and resources.
The following is the full list of all the resources that the 3 editions map to.
Standards
- OWASP Artificial Intelligence Security Verification Standard (AISVS)
- OWASP Application Security Verification Standard (ASVS) v4 (2019) and v5 (2025)
- OWASP Mobile Application Security Verification Standard (MASVS) v2.1
Maturity Models
OWASP Top 10:
Guides
- OWASP Automated Threats to Web Applications
- OWASP AI Testing Guide
- OWASP Mobile Application Security Testing Guide (MASTG) v1.7
Other sources:
- Mitre ATT&CK
- Mitre Atlas™
- Mitre CAPEC™ v3.9
- OWASP Dev Guide Web Application Checklist
- SAFECode Practical Security Stories and Security Tasks for Agile Development Environments (SAFECode) July 2012
- STRIDE
- PHANTOM-B
Other Security Gamification
If you are interested in using gaming for security, also see Elevation of Privilege: The Threat Modeling Game, Security Cards from the University of Washington, the commercial card game Control-Alt-Hack (presentation), OWASP Snakes and Ladders, OWASP Cumulus, OWASP Top 10 The Game, and web application security training tools incorporating gamification such as OWASP Juice Shop, Promptfall OWASP Security Shepherd, OWASP WrongSecrets and ITSEC Games.
Additionally, Adam Shostack maintains a list of tabletop security games and related resources at Tabletop Security Games + Cards.
Acknowledgements
Cornucopia is developed, maintained, updated and promoted by a worldwide team of volunteers. See our tribute page for a full list.
License
OWASP Cornucopia Website App Edition (formerly called Ecommerce Edition) was created by Colin Watson. OWASP Cornucopia Mobile App Edition was based on this and created by Johan Sydseter and Xavier Godard.
OWASP Cornucopia is open-source and can be downloaded free of charge from the OWASP Cornucopia GitHub repository. OWASP Cornucopia is free to use. Except, where otherwise noted, OWASP Cornucopia is licensed under the Creative Commons Attribution-ShareAlike 4.0 license, so you can copy, distribute and transmit the work, and you can adapt it, and use it commercially, but all provided that you attribute the work and if you alter, transform, or build upon this work, you may distribute the resulting work only under the same or similar license to this one.
OWASP and the OWASP logo are trademarks of the OWASP Foundation.