Sveriges mest populära poddar
The Application Security Podcast
The Application Security Podcast

Josh Grossman--AI & SAST: Is it a match?

40 min2 juni 2026

Om avsnittet

Traditional SAST is deterministic but shallow; AI can reason about context but may answer differently every time. Can the two approaches make each other better? Bounce Security CTO Josh Grossman explains why he built AGHAST, an open-source framework that combines static discovery with LLM analysis to investigate authorization, business-logic, and organization-specific risks. He walks through reducing false positives, importing SARIF, controlling token costs, and deciding where AI-assisted checks belong in developer workflows and CI. Josh also shares how he used Claude Code to build most of the project while retaining the architecture, product judgment, and code-review responsibility himself. The episode closes with AGHAST's roadmap, supported languages, practical adoption advice, and a guided demonstration of the tool.

Connect with Josh Grossman:
Josh Grossman on LinkedIn
OWASP AGHAST

Mentioned in this episode:
OWASP AGHAST
Semgrep
Cursor
Claude Code
SARIF
NDC Security
Black Hat
DEF CON
ISACA
Manicode Security

Follow the Application Security Podcast:
Home
X
LinkedIn
YouTube
Instagram
➜ Facebook

Chapters:
00:00 Meet Josh Grossman
01:11 Why Josh built AGHAST
04:22 Will AI disrupt AppSec tooling?
06:09 How AGHAST combines static analysis and AI
08:48 Deterministic rules and pure AI checks
10:23 Reducing SAST false positives
11:49 Using SARIF from existing scanners
12:46 Building AGHAST with Claude Code
14:14 The product specification and human judgment
17:48 How much code did the AI write?
19:05 The architect and product-manager mindset
21:08 Token economics becomes its own industry
22:54 Authorization and business-logic checks
25:55 Context makes custom rules valuable
28:15 Where AGHAST belongs in the workflow
30:11 Languages, frameworks, and COBOL
32:10 The AGHAST roadmap
34:20 Key takeaway and call to action
36:56 Training and conference appearances
37:29 AGHAST demonstration

The Application Security Podcast med Chris Romeo and Robert Hurlbut finns tillgänglig på flera plattformar. Informationen på denna sida kommer från offentliga podd-flöden.