
Mike Goodwin -- The OWASP Threat Dragon
Om avsnittet
Threat modeling is easier to adopt when its tools fit the way developers already work. Mike Goodwin joins Chris and Robert to introduce the early OWASP Threat Dragon project and explain why he wanted an accessible alternative to tools tied to a single operating system. They walk through creating diagrams, recording threats, and keeping models alongside application code in GitHub. Mike describes his plans for automated threat suggestions, workflow integration, and reminders that keep models from becoming stale. The discussion also considers collaboration, combining feature-level models, and what new users need to understand about STRIDE. This archive conversation documents the project’s initial ambitions and invites developers to help shape a simpler, more integrated approach to threat modeling.
The Application Security Podcast is brought to you by Security Journey.
About Security Journey
Security Journey provides application security education for developers and everyone in the software development lifecycle.
→ Learn more about Security Journey
Connect with Mike Goodwin:
→ Mike Goodwin on GitHub
→ OWASP Threat Dragon
Mentioned in this episode:
→ Threat Dragon source code
→ Microsoft Threat Modeling Tool
Follow the Application Security Podcast:
➜ Home
➜ X
➜ LinkedIn
➜ YouTube
➜ Instagram
➜ Facebook
Chapters:
00:00 Meet Mike Goodwin and OWASP Threat Dragon
01:19 A cloud migration sparks an interest in security
02:59 What Threat Dragon is designed to do
04:31 Why build another threat modeling tool?
06:17 The limitations of a Windows-only workflow
07:17 Creating a model in Threat Dragon
12:15 Threat generation and future capabilities
13:39 Keeping threat models beside code in GitHub
15:50 Connecting models to developer workflows
20:18 What organizations need from modeling tools
21:30 Concurrent editing and combining models
24:02 STRIDE and the knowledge new users need
25:00 The early roadmap toward beta and version one
27:18 Giving feedback and contributing
The Application Security Podcast med Chris Romeo and Robert Hurlbut finns tillgänglig på flera plattformar. Informationen på denna sida kommer från offentliga podd-flöden.