EPISODE · Jun 2, 2026 · 40 MIN
Josh Grossman--AI & SAST: Is it a match?
from The Application Security Podcast · host Chris Romeo and Robert Hurlbut
Traditional SAST is deterministic but shallow; AI can reason about context but may answer differently every time. Can the two approaches make each other better? Bounce Security CTO Josh Grossman explains why he built AGHAST, an open-source framework that combines static discovery with LLM analysis to investigate authorization, business-logic, and organization-specific risks. He walks through reducing false positives, importing SARIF, controlling token costs, and deciding where AI-assisted checks belong in developer workflows and CI. Josh also shares how he used Claude Code to build most of the project while retaining the architecture, product judgment, and code-review responsibility himself. The episode closes with AGHAST's roadmap, supported languages, practical adoption advice, and a guided demonstration of the tool.Connect with Josh Grossman:→ Josh Grossman on LinkedIn→ OWASP AGHASTMentioned in this episode:→ OWASP AGHAST→ Semgrep→ Cursor→ Claude Code→ SARIF→ NDC Security→ Black Hat→ DEF CON→ ISACA→ Manicode SecurityFollow the Application Security Podcast:➜ Home➜ X➜ LinkedIn➜ YouTube➜ Instagram➜ FacebookChapters:00:00 Meet Josh Grossman01:11 Why Josh built AGHAST04:22 Will AI disrupt AppSec tooling?06:09 How AGHAST combines static analysis and AI08:48 Deterministic rules and pure AI checks10:23 Reducing SAST false positives11:49 Using SARIF from existing scanners12:46 Building AGHAST with Claude Code14:14 The product specification and human judgment17:48 How much code did the AI write?19:05 The architect and product-manager mindset21:08 Token economics becomes its own industry22:54 Authorization and business-logic checks25:55 Context makes custom rules valuable28:15 Where AGHAST belongs in the workflow30:11 Languages, frameworks, and COBOL32:10 The AGHAST roadmap34:20 Key takeaway and call to action36:56 Training and conference appearances37:29 AGHAST demonstration
Embed this episode
What this episode covers
Traditional SAST is deterministic but shallow; AI can reason about context but may answer differently every time. Can the two approaches make each other better? Bounce Security CTO Josh Grossman explains why he built AGHAST, an open-source framework that combines static discovery with LLM analysis to investigate authorization, business-logic, and organization-specific risks. He walks through reducing false positives, importing SARIF, controlling token costs, and deciding where AI-assisted che...
Ready to play
Josh Grossman--AI & SAST: Is it a match?
No transcript for this episode yet
Similar Episodes
No similar episodes found.
Similar Podcasts
No similar podcasts found.