EPISODE · Apr 18, 2023 · 49 MIN
Christian Frichot -- Threat Modeling with hcltm
from The Application Security Podcast · host Chris Romeo and Robert Hurlbut
Christian Frichot, an AppSec hacker, security leader, and developer of hcltm. He discusses the DevOps threat modeling tool he dreamed up and built. The tech was created to fit into developers' workflows and leverage tools they are familiar with. hcltm is designed to drive valuable change and be updated and maintained easily by software engineers. It is a developer-centric software product not heavily opinionated on diagramming, allowing users to employ their preferred methods for threat modeling. The solution is still evolving, and Frichot is open to user feedback and suggestions to improve it. He encourages people to try hcltm and see if it fits their threat modeling needs, as everyone approaches the process differently.The Application Security Podcast is brought to you by Security Journey.About Security JourneyHere's a list of things that Christian Frichot is.→ Learn more about Security JourneyConnect with Christian Frichot:→ hcltm (now threatcl) on GitHub→ TerraformMentioned in this episode:→ hcltm (now threatcl) on GitHub→ Terraform→ Semgrep→ Open Threat Model (OTM)→ Microsoft Security Development Lifecycle (SDL)→ OWASP AI Security and Privacy GuideFollow the Application Security Podcast:➜ Home➜ X➜ LinkedIn➜ YouTube➜ Instagram➜ FacebookChapters:00:00 Meet Christian Frichot: Threat Modeling with hcltm02:01 We're super excited to have Christian Frichot with us this evening05:58 Yeah, excellent. So, I have so many questions, and we haven't10:17 Yeah, so Christian, so this new tool that has been around17:45 There a structured set of language and commands and things that24:34 Yeah. And look, that's definitely a gap in the tool. Like26:48 With that in mind, so there's an assumption, it sounds like29:35 Yeah. I think this is the future, right31:13 Yeah. And it is quite funny. I think that's the other35:52 I kind of like those sorts of, you know, Unix philosophy37:30 To past episodes, 'cause you were talking about Microsoft and them40:28 You see it as a bidirectional communication or a unidirectional communication42:42 Yeah. Yeah. We're starting to see them. I mean, I've started45:27 Yeah. Have you— I was trying to figure out, have you47:46 The best place for them to go is the GitHub repo
Embed this episode
What this episode covers
Christian Frichot, an AppSec hacker, security leader, and developer of hcltm. He discusses the DevOps threat modeling tool he dreamed up and built. The tech was created to fit into developers' workflows and leverage tools they are familiar with. hcltm is designed to drive valuable change and be updated and maintained easily by software engineers. It is a developer-centric software product not heavily opinionated on diagramming, allowing users to employ their preferred methods for threat model...
Ready to play
Christian Frichot -- Threat Modeling with hcltm
No transcript for this episode yet
Similar Episodes
No similar episodes found.
Similar Podcasts
No similar podcasts found.