Welcome to the Boring AppSec Podcast! In Episode 5, we dig deep into what threat modeling is from a practitioner's perspective. We compare it with design reviews and discuss when/how/why of threat modeling. In the end, we wrap up by talking about how Gen AI could help threat modeling significantly.
References:
We will try and add information about all the references we make here. Please enter rabbit holes at will :)
- Threat modeling manifesto - Threatmodelingmanifesto.org
- STRIDE framework - https://en.wikipedia.org/wiki/STRIDE_(security)
- Tools for threat modeling
- https://learn.microsoft.com/en-us/azure/security/develop/threat-modeling-tool
- https://www.iriusrisk.com/threat-modeling/freemium
- https://owasp.org/www-project-threat-dragon/
- https://excalidraw.com/
- https://www.securitycompass.com/sdelements/
- Talks on threat modeling
- Articles - https://www.scaletozero.com/episodes/understanding-threat-modeling-with-jeevan-singh/
- Gen AI related threat modeling tools/companies
- Stride GPT- https://stridegpt.streamlit.app/
- Nullify - https://www.nullify.ai/
- Remysec - https://www.remysec.com/
- Seezo - https://seezo.io/
Contacting Anshuman
- LinkedIn: https://www.linkedin.com/in/anshumanbhartiya/
- Twitter: https://twitter.com/anshuman_bh
- Website: https://anshumanbhartiya.com/
- Instagram: https://www.instagram.com/anshuman.bhartiya/
- YouTube: https://www.youtube.com/@AnshumanBhartiya
Contacting Sandesh
Fler avsnitt av The Boring AppSec Podcast
Visa alla avsnitt av The Boring AppSec PodcastThe Boring AppSec Podcast med The Boring AppSec Podcast finns tillgänglig på flera plattformar. Informationen på denna sida kommer från offentliga podd-flöden.
