DREAD Risk Scoring Calculator
Score security findings with the DREAD model across damage, reproducibility, exploitability, affected users and discoverability, and rank a set of issues by their combined score.
Last reviewed by the Radiatus Cloud team
Need this handled by experts?
Radiatus runs VAPT, managed SOC & security engineering for regulated teams.
A structured alternative to arguing about severity
DREAD scores a finding on five dimensions: damage potential, reproducibility, exploitability, affected users and discoverability. Each is rated on a scale, and the average or sum gives a comparable number. Microsoft developed it alongside STRIDE and later moved away from it, because the dimensions are subjective and different assessors produce different scores for the same finding. That criticism is fair and it applies equally to every severity rating scheme, including the ones people use instead.
Its value is in the conversation, not the number
The reason to use DREAD is that it forces five separate questions where teams otherwise ask one. A finding that is catastrophic but requires physical access and insider knowledge scores very differently from one that is moderate but trivially discoverable by an automated scanner and affects everyone. Both might be called high severity in a report. Scoring them separately makes the difference explicit and gives the remediation queue an order that can be defended.
Discoverability is the contested dimension
Some practitioners drop discoverability entirely, arguing that assuming an attacker will find any given issue is the only safe posture and that scoring it low amounts to security through obscurity. The counterargument is that a bug reachable only through an undocumented internal endpoint genuinely is less likely to be exploited than one on the login page. The calculator lets you exclude it so both approaches are available, and it reports the score with and without it.
Related tools
- Password Strength Checker — Measure password strength by entropy and pattern analysis rather than character-class rules. Checked entirely in your browser.
- Password Generator — Generate strong random passwords and passphrases in your browser using the Web Crypto API. Nothing is transmitted, logged or stored.
- Hash Generator — Generate MD5, SHA-1, SHA-256 and SHA-512 hashes in your browser. Compare checksums and verify file integrity with nothing uploaded to a server.
- Base64 Encoder/Decoder — Encode and decode Base64 in your browser, including URL-safe Base64 and UTF-8 text. Handles files and data URIs locally with nothing uploaded.
Frequently Asked Questions
Is DREAD still used?
Microsoft moved away from it and CVSS is now the industry standard for published vulnerabilities. DREAD survives in internal threat modelling because its dimensions map more naturally to a specific application than CVSS base metrics do, and because it is quicker to apply.
How is the score calculated?
Each dimension is rated, and the ratings are averaged or summed. This tool reports the average on a 1 to 10 scale, which is the more common modern form, along with the raw total for teams that use it.
Should discoverability be included?
It is contested. Excluding it treats every issue as if an attacker will find it, which is the conservative posture. Including it acknowledges that a bug behind an undocumented internal endpoint is genuinely less likely to be exploited. The tool reports both.
How do I keep scoring consistent between assessors?
Write down what each rating level means for your own context before scoring anything, and have two people score the same finding independently as a calibration exercise. Consistency comes from shared definitions, not from the model.
Should I use DREAD or CVSS?
CVSS for anything you will publish or compare against external data, because it is what everyone else uses. DREAD for internal threat modelling where the dimensions map better to your own application and where the discussion matters more than the number.
Privacy & Security
Everything runs in your browser; nothing is uploaded.
How to Use
Add each finding and rate it on the five DREAD dimensions to get a ranked risk list.
Disclaimer: This tool is provided "as is" without warranty of any kind. Results are for educational and utility purposes.
Related Tools
Password Strength Checker
SecurityMeasure password strength by entropy and pattern analysis rather than character-class rules. Checked entirely in your browser.
Password Generator
SecurityGenerate strong random passwords and passphrases in your browser using the Web Crypto API. Nothing is transmitted, logged or stored.
Hash Generator
SecurityGenerate MD5, SHA-1, SHA-256 and SHA-512 hashes in your browser. Compare checksums and verify file integrity with nothing uploaded to a server.