
Abhay Bhargav -- Threat Modeling as Code
Om avsnittet
A threat model that lives in an old document rarely keeps pace with the code it describes. Abhay Bhargav explains how threat modeling as code can connect user stories, abuse cases, threat scenarios, and specific controls inside an evolving development process. He describes choosing YAML as a familiar format, compares that approach with behavior-driven specifications, and shows how the result can help both engineering teams and security testers. The conversation introduces Threat Playbook and explores turning concrete mitigations into an attack model and useful testing direction. Abhay also discusses the challenge of automating tools with different interfaces, including ZAP and nodejsscan. The episode makes the case for keeping threat information actionable, versionable, and close to the people building the application.
The Application Security Podcast is brought to you by Security Journey.
About Security Journey
Security Journey provides application security education for developers and everyone in the software development lifecycle.
→ Learn more about Security Journey
Connect with Abhay Bhargav:
→ Abhay Bhargav on LinkedIn
→ we45
Mentioned in this episode:
→ Threat Playbook
→ ZAP
→ nodejsscan
Follow the Application Security Podcast:
➜ Home
➜ X
➜ LinkedIn
➜ YouTube
➜ Instagram
➜ Facebook
Chapters:
00:00 Threat modeling as code with Abhay Bhargav
01:51 Early work in PCI and security
03:37 Why traditional threat models become stale
06:48 From user stories to abuse cases and threats
08:32 Integrating the model into development
09:16 YAML specifications and alternative approaches
11:23 Benefits for DevOps and security teams
14:13 Attack models and specific mitigations
17:26 Introducing Threat Playbook
20:40 The challenge of automated security pipelines
22:54 Python and tool choices
23:26 ZAP, nodejsscan, and npm audit
26:37 Sharing the workshop materials
The Application Security Podcast med Chris Romeo and Robert Hurlbut finns tillgänglig på flera plattformar. Informationen på denna sida kommer från offentliga podd-flöden.