Attack trees decompose goals into possible paths

Start with what the attacker wants and work backwards through every way they could get it.

It produces a structure rather than a list, which makes it obvious when several branches share a single control, and when an expensive mitigation only closes one route out of five. It also handles non-technical branches naturally: bribery and physical access sit in the tree alongside exploits.

More on Threat modelling