Sveriges mest populära poddar
The Application Security Podcast
The Application Security Podcast

Izar Tarandach — Command line threat modeling with pytm

29 min24 april 2019

Om avsnittet

What if developers could describe threats in the same place they describe their software? Izar Tarandach introduces pytm, a Python framework that turns a system description into diagrams and a starting list of threats. He explains why the team built a command line approach, how element attributes drive threat identification, and why small models belong beside the code they describe. Chris and Izar explore possible CI/CD integration, the knowledge developers need to get started, and the limits of automating a conversation about design. The episode offers a practical starting point: clone the sample model, make its diagram resemble your system, then use that shared picture to discover and discuss the risks automation cannot resolve alone.

The Application Security Podcast is brought to you by Security Journey.

About Security Journey
Security Journey provides application security education for developers and everyone in the software development lifecycle.
Learn more about Security Journey

Connect with Izar Tarandach:
Izar Tarandach on LinkedIn
OWASP pytm

Mentioned in this episode:
pytm source and examples
Microsoft Threat Modeling Tool
Graphviz

Follow the Application Security Podcast:
Home
X
LinkedIn
YouTube
Instagram
➜ Facebook

Chapters:
00:00 Command line threat modeling with Izar Tarandach
01:10 Izar’s security origin story
05:26 What pytm does and why the team built it
10:54 Where the threat rules come from
12:57 How developers respond to modeling in code
14:47 Keeping threat models beside source code
15:38 Potential CI/CD integration
17:48 Small models and detecting design drift
18:43 How much security knowledge developers need
19:53 Where whiteboard conversations still matter
20:55 A graphical interface without losing the code
22:12 Using pytm with applications in other languages
25:21 Getting started with the sample model
26:25 Finding the project and community

The Application Security Podcast med Chris Romeo and Robert Hurlbut finns tillgänglig på flera plattformar. Informationen på denna sida kommer från offentliga podd-flöden.