
Tony UV -- Threat Libraries in the Cloud
Om avsnittet
A list of weaknesses is not the same thing as an understanding of the threats facing a business. Tony UV returns to explain how a threat library can connect industry intelligence with evidence from an organization’s own systems. He distinguishes threats, attacks, and vulnerabilities, then describes how cloud logs and configuration signals can add context to a threat model. The conversation examines the feedback loop between modeling, detection, and real incidents, with examples involving sabotage, data loss, and extortion. Tony recommends starting with a manageable set of business concerns, substantiating them with evidence, and mapping the relevant attack paths and technologies. His approach gives teams a way to make threat modeling reflect what could actually harm the operation they support.
The Application Security Podcast is brought to you by Security Journey.
About Security Journey
Security Journey provides application security education for developers and everyone in the software development lifecycle.
→ Learn more about Security Journey
Connect with Tony UcedaVelez:
→ Tony UV on LinkedIn
→ VerSprite
Mentioned in this episode:
→ MITRE CAPEC
→ MITRE ATT&CK
→ AWS CloudTrail
→ FS-ISAC
Follow the Application Security Podcast:
➜ Home
➜ X
➜ LinkedIn
➜ YouTube
➜ Instagram
➜ Facebook
Chapters:
00:00 Threat libraries in the cloud with Tony UV
01:16 Continuing the threat modeling conversation
02:30 External intelligence and internal evidence
05:25 Validating threats in business context
08:12 How the library supports a threat model
12:09 Cloud platforms as sources of threat context
18:13 The feedback loop between models and incidents
18:55 Connecting business threats to attack patterns
22:23 Starting with a manageable threat library
23:14 Beyond STRIDE: evidence, extortion, and business impact
The Application Security Podcast med Chris Romeo and Robert Hurlbut finns tillgänglig på flera plattformar. Informationen på denna sida kommer från offentliga podd-flöden.