
What's the Elevation of Privilege Game?
Elevation of Privilege (EoP), created by Adam Shostack, is a game designed for developers that makes the process of threat modeling more approachable and engaging. Instead of working through lengthy checklists, players use a card game format to uncover vulnerabilities in the design stage of their development process, making security discussions more interactive and collaborative.

What's in the deck?
There are 88 cards in the deck, with 78 covering common security pitfalls to help players identify real threats. The cards follow the STRIDE framework, breaking down threats into six suits or key categories: Spoofing • Tampering • Repudiation • Information Disclosure • Denial of Service • Elevation of Privilege
Use the game with any team, in any industry. Perfect for Agile and DevOps workflows.

How to play?
- Start by sketching a simple diagram of the system on a whiteboard, paper, or digital tool, just enough to show key components and data flows.
- Shuffle the deck and deal all the cards to 3-6 players.
- The player with the 2 of Tampering kicks things off. Read your card aloud and describe if and how the threat could impact the system. Record the issue.
- Play proceeds to the next player who picks a card from their hand that belongs to the same suit which in the first round is Tampering.
- Each round, they must follow the suit that was led, with the highest-value card winning unless an Elevation of Privilege (EoP) card is played, in which case the highest EoP card wins. The round’s winner leads the next turn, and play continues until all cards are used.
- After the game, the team reviews identified threats and discusses how to address them, turning gameplay insights into actionable security improvements.

Remote Teams? We've got you covered!
- Send physical decks to each team member, making the most of our bulk pricing and multi-address fulfilment.
- Use our online hand dealing tool Croupier to generate random hands for each player.
- Email the hands to the players so they can pick out their cards from their decks ahead of the session and be ready to play.