VITI Security

Fable 5 for Security Teams: Assisting Threat-Modeling Sessions

by VITI Security TeamJun 25, 2026

Fable 5 can cut the prep time and structure overhead of threat-modeling sessions, letting security analysts focus on judgment calls rather than busywork.

Fable 5 for Security Teams: Assisting Threat-Modeling Sessions - VITI Security

Fable 5 for security teams earns its keep most clearly in one place: threat-modeling sessions. It can draft attack-surface inventories, map data flows, and generate STRIDE-style threat lists in minutes - work that used to take hours of whiteboard prep. A human analyst still owns every decision; Fable 5 just removes the grind so the team can focus on the hard judgment calls.

What can Fable 5 actually do in a threat-modeling session?

What prep work does Fable 5 handle before the session starts?
Feed it your architecture diagram, a plain-English system description, or even a rough data-flow sketch, and Fable 5 can produce a structured asset inventory, a list of trust boundaries, and a first-pass data-flow diagram in text form. This gives the team a concrete starting point instead of a blank whiteboard. Expect to spend 10-15 minutes reviewing and correcting the output before the session - do not skip that step.
Can it generate STRIDE threat lists automatically?
Yes, and this is where it saves the most time. Paste in your component list and Fable 5 will produce a STRIDE table - Spoofing, Tampering, Repudiation, Information Disclosure, Denial of Service, Elevation of Privilege - mapped to each component. The threats it surfaces are pattern-matched from training data, so they are a solid starting checklist, not a finished risk register. Your team validates severity, likelihood, and mitigations.
How does it help when the team gets stuck on a specific attack path?
You can describe a scenario in plain English - 'attacker has read access to the message queue; what can they do?' - and Fable 5 will reason through potential lateral-movement paths, data it could exfiltrate, and second-order effects. Use this as a thinking aid, not a ground-truth answer. A senior analyst should pressure-test each path the model surfaces.

How do teams use Fable 5 for security teams inside a live session?

What is the most practical workflow for using it during the meeting itself?
Assign one person as the Fable 5 operator - they type queries and paste responses into the shared screen. The rest of the team debates and annotates. Typical flow: (1) paste the current component under review, (2) ask for STRIDE threats, (3) team accepts, edits, or discards each item, (4) accepted items go straight into the risk register. This keeps the AI in a support role and keeps human reasoning visible to everyone in the room.
Can Fable 5 help write up findings after the session?
Yes. Paste the accepted threat list and mitigation notes from the session and ask Fable 5 to draft the threat-model report section. It will structure the content into asset, threat, risk level, and mitigation columns. You still need a reviewer to check that no context was lost between the whiteboard and the written output - but the drafting time drops from two hours to under thirty minutes.

What are the real limits of Fable 5 for security teams in threat modeling?

Will it catch every threat?
No. Fable 5 is pattern-based. Novel attack chains, business-logic flaws specific to your application, and threats that require deep knowledge of your internal environment are all areas where it will underperform. Treat its threat list as 'threats to consider' rather than 'threats confirmed'. Always close the session with an open-ended question to the human team: 'What did the model miss?'
Is it safe to paste architecture diagrams and data-flow details into Fable 5?
Check your organisation's data-handling policy before pasting anything sensitive. If your architecture diagram contains internal IP ranges, credentials, or proprietary system names, anonymise them first - replace specifics with generic labels like 'internal API gateway' or 'auth service'. The threat-modeling value you get is the same; the exposure risk is much lower.
Who is accountable for the final threat model?
Always a human. Fable 5 assists - it does not sign off. The security analyst, architect, or CISO who owns the system is accountable for the completeness and accuracy of the threat model. Make this explicit in your team's process documentation so it is never ambiguous.

A repeatable Fable 5 threat-modeling workflow

01

1 - Prepare inputs

Gather your system description, component list, and data-flow notes. Anonymise any sensitive details before pasting.

02

2 - Generate asset inventory

Ask Fable 5 to list assets, trust boundaries, and data stores. Review and correct the output before the session opens.

03

3 - Run STRIDE analysis per component

Feed each component in turn and collect the STRIDE threat table. Duplicate threats across components are normal - keep them until de-duplication in step 5.

04

4 - Pressure-test attack paths

For high-priority threats, ask Fable 5 to reason through lateral-movement or escalation scenarios. A senior analyst reviews each path.

05

5 - Human review and triage

Team votes on severity and likelihood. Items without consensus get a dedicated discussion slot. AI output never advances without a human accept.

06

6 - Draft the report

Paste accepted items into Fable 5 to generate the structured report section. A reviewer checks for gaps before it is finalised.

Threat-modeling session: with and without Fable 5

FeatureWithout Fable 5With Fable 5
Asset inventory prepManual, 1-2 hoursAI draft in minutes, 15-min review
STRIDE threat listBuilt from memory and experienceGenerated checklist, team validates
Attack-path reasoningRelies on whoever is in the roomAI surfaces paths, analyst pressure-tests
Report drafting1-2 hours post-sessionUnder 30 minutes with AI draft
Human accountabilityFullFull - unchanged

Where Fable 5 saves time in a typical session

~15 min
To review an AI-generated asset inventory vs. building one from scratch
6 threat types
Covered per component in a single STRIDE pass
1 operator
Needed to run Fable 5 queries while the rest of the team debates

Want a structured approach to AI-assisted threat modeling?

VITI Security works with SMBs to build repeatable security processes - including where and how to bring AI tools into the workflow safely. Talk to our team or explore our managed security services.