EPISODE · Apr 24, 2019 · 28 MIN
Izar Tarandach — Command line threat modeling with pytm
from The Application Security Podcast · host Chris Romeo and Robert Hurlbut
What if developers could describe threats in the same place they describe their software? Izar Tarandach introduces pytm, a Python framework that turns a system description into diagrams and a starting list of threats. He explains why the team built a command line approach, how element attributes drive threat identification, and why small models belong beside the code they describe. Chris and Izar explore possible CI/CD integration, the knowledge developers need to get started, and the limits of automating a conversation about design. The episode offers a practical starting point: clone the sample model, make its diagram resemble your system, then use that shared picture to discover and discuss the risks automation cannot resolve alone.The Application Security Podcast is brought to you by Security Journey.About Security JourneySecurity Journey provides application security education for developers and everyone in the software development lifecycle.→ Learn more about Security JourneyConnect with Izar Tarandach:→ Izar Tarandach on LinkedIn→ OWASP pytmMentioned in this episode:→ pytm source and examples→ Microsoft Threat Modeling Tool→ GraphvizFollow the Application Security Podcast:➜ Home➜ X➜ LinkedIn➜ YouTube➜ Instagram➜ FacebookChapters:00:00 Command line threat modeling with Izar Tarandach01:10 Izar’s security origin story05:26 What pytm does and why the team built it10:54 Where the threat rules come from12:57 How developers respond to modeling in code14:47 Keeping threat models beside source code15:38 Potential CI/CD integration17:48 Small models and detecting design drift18:43 How much security knowledge developers need19:53 Where whiteboard conversations still matter20:55 A graphical interface without losing the code22:12 Using pytm with applications in other languages25:21 Getting started with the sample model26:25 Finding the project and community
Embed this episode
What this episode covers
What if developers could describe threats in the same place they describe their software? Izar Tarandach introduces pytm, a Python framework that turns a system description into diagrams and a starting list of threats. He explains why the team built a command line approach, how element attributes drive threat identification, and why small models belong beside the code they describe. Chris and Izar explore possible CI/CD integration, the knowledge developers need to get started, and the limits...
Ready to play
Izar Tarandach — Command line threat modeling with pytm
No transcript for this episode yet
Similar Episodes
No similar episodes found.
Similar Podcasts
No similar podcasts found.