# Zero-Day Threat Model
**Entity class:** Adversarial-systems analogy
## Definition
A **zero-day threat model** treats an attack path as functionally zero-day-like when the defensive architecture has not converted the possibility into controls, training, sensing, or response, even if fragments of the idea have appeared before. It extends zero-day reasoning from software vulnerabilities to institutional assumptions while preserving the difference between analogy and literal software exploitation.
## Relevance to this collection
September 11 is a strong case: suicide hijacking had been contemplated, but the threat had not been operationalized throughout aviation security and response. The attack sat between pure novelty and an unpatched known weakness.
## Relationships
- **master collection:** [[collections/Terrorism, Counterterrorism, and the Intelligence Environment|Terrorism, Counterterrorism, and the Intelligence Environment]].
- **convergence:** [[wiki/Counterterrorism-Cybersecurity Convergence|Counterterrorism–Cybersecurity Convergence]].
## Sources / Provenance
- [National Commission on Terrorist Attacks Upon the United States, *The 9/11 Commission Report*, July 22, 2004](https://www.9-11commission.gov/report/911Report_Ch11.htm).
**As of:** 2026-09-23