Why does the threat-modeling workflow begin by inspecting files and application routes?
Listing routes automatically patches every vulnerability in the application.
Observable behavior reveals entry points, stored data, and privileged functions that the model must represent.
Route output alone is a complete threat model.
A threat model should be completed without learning what the service does.