Christian Frichot -- Threat Modeling with hcltm episode artwork

EPISODE · Apr 18, 2023 · 49 MIN

Christian Frichot -- Threat Modeling with hcltm

from The Application Security Podcast · host Chris Romeo and Robert Hurlbut

Christian Frichot, an AppSec hacker, security leader, and developer of hcltm. He discusses the DevOps threat modeling tool he dreamed up and built. The tech was created to fit into developers' workflows and leverage tools they are familiar with. hcltm is designed to drive valuable change and be updated and maintained easily by software engineers. It is a developer-centric software product not heavily opinionated on diagramming, allowing users to employ their preferred methods for threat modeling. The solution is still evolving, and Frichot is open to user feedback and suggestions to improve it. He encourages people to try hcltm and see if it fits their threat modeling needs, as everyone approaches the process differently.The Application Security Podcast is brought to you by Security Journey.About Security JourneyHere's a list of things that Christian Frichot is.→ Learn more about Security JourneyConnect with Christian Frichot:→ hcltm (now threatcl) on GitHub→ TerraformMentioned in this episode:→ hcltm (now threatcl) on GitHub→ Terraform→ Semgrep→ Open Threat Model (OTM)→ Microsoft Security Development Lifecycle (SDL)→ OWASP AI Security and Privacy GuideFollow the Application Security Podcast:➜ Home➜ X➜ LinkedIn➜ YouTube➜ Instagram➜ FacebookChapters:00:00 Meet Christian Frichot: Threat Modeling with hcltm02:01 We're super excited to have Christian Frichot with us this evening05:58 Yeah, excellent. So, I have so many questions, and we haven't10:17 Yeah, so Christian, so this new tool that has been around17:45 There a structured set of language and commands and things that24:34 Yeah. And look, that's definitely a gap in the tool. Like26:48 With that in mind, so there's an assumption, it sounds like29:35 Yeah. I think this is the future, right31:13 Yeah. And it is quite funny. I think that's the other35:52 I kind of like those sorts of, you know, Unix philosophy37:30 To past episodes, 'cause you were talking about Microsoft and them40:28 You see it as a bidirectional communication or a unidirectional communication42:42 Yeah. Yeah. We're starting to see them. I mean, I've started45:27 Yeah. Have you— I was trying to figure out, have you47:46 The best place for them to go is the GitHub repo

Episode metadata supplied by the publisher feed · Published Apr 18, 2023

Embed this episode

Christian Frichot, an AppSec hacker, security leader, and developer of hcltm. He discusses the DevOps threat modeling tool he dreamed up and built. The tech was created to fit into developers' workflows and leverage tools they are familiar with. hcltm is designed to drive valuable change and be updated and maintained easily by software engineers. It is a developer-centric software product not heavily opinionated on diagramming, allowing users to employ their preferred methods for threat model...

Distinct summary based on available episode metadata or transcript content.

Ready to play

Christian Frichot -- Threat Modeling with hcltm

0:00 49:27

No transcript for this episode yet

We transcribe on demand. Request one and we'll notify you when it's ready — usually under 10 minutes.

No similar episodes found.

No similar podcasts found.

Frequently Asked Questions

How long is this episode of The Application Security Podcast?

This episode is 49 minutes long.

When was this The Application Security Podcast episode published?

This episode was published on April 18, 2023.

Can I download this The Application Security Podcast episode?

Yes. Use the download control on the episode player to save the publisher-provided media file.
URL copied to clipboard!