SAP Threat Modeling Tool
The SAP Threat Modeling Tool is an on-premise, open-source web application that analyzes and visualizes the connections between your SAP systems - helping you identify security risks and vulnerabilities across your landscape.
Get it on GitHub How it worksWhat is SAP threat modeling?
SAP threat modeling is the practice of mapping and visualizing the connections between your SAP systems to identify security risks before attackers exploit them. The RedRays SAP Threat Modeling Tool does this automatically - you input your SAP credentials, it scans for connections and renders a clear network map with the risks highlighted.
How it works
From SAP credentials to a visual threat model in four steps.
Connect
Enter your SAP credentials - the tool runs on-premise, so nothing leaves your environment.
Scan for connections
The tool discovers the connections and trust relationships between your SAP systems.
Visualize the network
It renders an interactive map of your SAP landscape, so you can see how systems are linked at a glance.
Identify security risks
Risky connections and exposure points are highlighted, turning your landscape map into an actionable threat model.
Features
SAP credential input
Point the tool at your SAP systems with simple credential input.
Connection scanning
Automatically scans for connections and trust links between systems.
Network visualization
Renders a clear, interactive map of your SAP landscape and its links.
Risk identification
Surfaces the security risks and vulnerabilities hidden in those connections.
Runs in your environment
An on-premise web application - your SAP data never leaves your network.
Free & open source
Fully open-source and free to use, inspect and extend on GitHub.
See it in action
Scanning, visualizing and mapping SAP system connections. Click any screenshot to enlarge.
Go further with RedRays
The open-source tool maps your risks - these services and the full platform help you fix them.
SAP threat modeling FAQ
What is the SAP Threat Modeling Tool?
It is an on-premise, open-source web application from RedRays that analyzes and visualizes the connections between your SAP systems, helping you identify security risks and vulnerabilities across your landscape.
Is the SAP Threat Modeling Tool free and open source?
Yes. It is fully open source and free to use, inspect and extend. The code is available on GitHub at github.com/redrays-io/SAP-Threat-Modeling.
How does the SAP threat modeling tool work?
You input your SAP credentials, the tool scans for connections between your SAP systems, visualizes the network as an interactive map, and highlights the security risks in those connections.
Does the tool run on-premise?
Yes. It is an on-premise web application, so your SAP credentials and data stay inside your own environment and never leave your network.
How is it different from the RedRays Security Platform?
The open-source tool is a light version of the Threat Modeling module from the full RedRays Security Platform, which adds deeper detection - 1,000+ configuration issues and 4,000+ vulnerabilities across SAP - and enterprise features.
Want the full Threat Modeling module?
Get the open-source tool on GitHub - or talk to us about the full RedRays Security Platform.
