If you're looking for concrete resources with steps on how to perform threat modelling, I've used the Microsoft SDL Threat Modelling tool/process [1].
It's pretty Microsoft skewed (lots of references to Azure resources), but is a reasonable way to start thinking about the topic.
[1]: https://www.microsoft.com/en-us/securityengineering/sdl/thre...