Izar Tarandach — Command line threat modeling with pytm episode artwork

EPISODE · Apr 24, 2019 · 28 MIN

Izar Tarandach — Command line threat modeling with pytm

from The Application Security Podcast · host Chris Romeo and Robert Hurlbut

What if developers could describe threats in the same place they describe their software? Izar Tarandach introduces pytm, a Python framework that turns a system description into diagrams and a starting list of threats. He explains why the team built a command line approach, how element attributes drive threat identification, and why small models belong beside the code they describe. Chris and Izar explore possible CI/CD integration, the knowledge developers need to get started, and the limits of automating a conversation about design. The episode offers a practical starting point: clone the sample model, make its diagram resemble your system, then use that shared picture to discover and discuss the risks automation cannot resolve alone.The Application Security Podcast is brought to you by Security Journey.About Security JourneySecurity Journey provides application security education for developers and everyone in the software development lifecycle.→ Learn more about Security JourneyConnect with Izar Tarandach:→ Izar Tarandach on LinkedIn→ OWASP pytmMentioned in this episode:→ pytm source and examples→ Microsoft Threat Modeling Tool→ GraphvizFollow the Application Security Podcast:➜ Home➜ X➜ LinkedIn➜ YouTube➜ Instagram➜ FacebookChapters:00:00 Command line threat modeling with Izar Tarandach01:10 Izar’s security origin story05:26 What pytm does and why the team built it10:54 Where the threat rules come from12:57 How developers respond to modeling in code14:47 Keeping threat models beside source code15:38 Potential CI/CD integration17:48 Small models and detecting design drift18:43 How much security knowledge developers need19:53 Where whiteboard conversations still matter20:55 A graphical interface without losing the code22:12 Using pytm with applications in other languages25:21 Getting started with the sample model26:25 Finding the project and community

Episode metadata supplied by the publisher feed · Published Apr 24, 2019

Embed this episode

What if developers could describe threats in the same place they describe their software? Izar Tarandach introduces pytm, a Python framework that turns a system description into diagrams and a starting list of threats. He explains why the team built a command line approach, how element attributes drive threat identification, and why small models belong beside the code they describe. Chris and Izar explore possible CI/CD integration, the knowledge developers need to get started, and the limits...

Distinct summary based on available episode metadata or transcript content.

Ready to play

Izar Tarandach — Command line threat modeling with pytm

0:00 28:46

No transcript for this episode yet

We transcribe on demand. Request one and we'll notify you when it's ready — usually under 10 minutes.

No similar episodes found.

No similar podcasts found.

Frequently Asked Questions

How long is this episode of The Application Security Podcast?

This episode is 28 minutes long.

When was this The Application Security Podcast episode published?

This episode was published on April 24, 2019.

Can I download this The Application Security Podcast episode?

Yes. Use the download control on the episode player to save the publisher-provided media file.
URL copied to clipboard!