
Christian Frichot -- Threat Modeling with hcltm
Om avsnittet
Christian Frichot, an AppSec hacker, security leader, and developer of hcltm. He discusses the DevOps threat modeling tool he dreamed up and built. The tech was created to fit into developers' workflows and leverage tools they are familiar with. hcltm is designed to drive valuable change and be updated and maintained easily by software engineers. It is a developer-centric software product not heavily opinionated on diagramming, allowing users to employ their preferred methods for threat modeling. The solution is still evolving, and Frichot is open to user feedback and suggestions to improve it. He encourages people to try hcltm and see if it fits their threat modeling needs, as everyone approaches the process differently.
The Application Security Podcast is brought to you by Security Journey.
About Security Journey
Here's a list of things that Christian Frichot is.
→ Learn more about Security Journey
Connect with Christian Frichot:
→ hcltm (now threatcl) on GitHub
→ Terraform
Mentioned in this episode:
→ hcltm (now threatcl) on GitHub
→ Terraform
→ Semgrep
→ Open Threat Model (OTM)
→ Microsoft Security Development Lifecycle (SDL)
→ OWASP AI Security and Privacy Guide
Follow the Application Security Podcast:
➜ Home
➜ X
➜ LinkedIn
➜ YouTube
➜ Instagram
➜ Facebook
Chapters:
00:00 Meet Christian Frichot: Threat Modeling with hcltm
02:01 We're super excited to have Christian Frichot with us this evening
05:58 Yeah, excellent. So, I have so many questions, and we haven't
10:17 Yeah, so Christian, so this new tool that has been around
17:45 There a structured set of language and commands and things that
24:34 Yeah. And look, that's definitely a gap in the tool. Like
26:48 With that in mind, so there's an assumption, it sounds like
29:35 Yeah. I think this is the future, right
31:13 Yeah. And it is quite funny. I think that's the other
35:52 I kind of like those sorts of, you know, Unix philosophy
37:30 To past episodes, 'cause you were talking about Microsoft and them
40:28 You see it as a bidirectional communication or a unidirectional communication
42:42 Yeah. Yeah. We're starting to see them. I mean, I've started
45:27 Yeah. Have you— I was trying to figure out, have you
47:46 The best place for them to go is the GitHub repo
The Application Security Podcast med Chris Romeo and Robert Hurlbut finns tillgänglig på flera plattformar. Informationen på denna sida kommer från offentliga podd-flöden.