Josh Grossman--AI & SAST: Is it a match? episode artwork

EPISODE · Jun 2, 2026 · 40 MIN

Josh Grossman--AI & SAST: Is it a match?

from The Application Security Podcast · host Chris Romeo and Robert Hurlbut

Traditional SAST is deterministic but shallow; AI can reason about context but may answer differently every time. Can the two approaches make each other better? Bounce Security CTO Josh Grossman explains why he built AGHAST, an open-source framework that combines static discovery with LLM analysis to investigate authorization, business-logic, and organization-specific risks. He walks through reducing false positives, importing SARIF, controlling token costs, and deciding where AI-assisted checks belong in developer workflows and CI. Josh also shares how he used Claude Code to build most of the project while retaining the architecture, product judgment, and code-review responsibility himself. The episode closes with AGHAST's roadmap, supported languages, practical adoption advice, and a guided demonstration of the tool.Connect with Josh Grossman:→ Josh Grossman on LinkedIn→ OWASP AGHASTMentioned in this episode:→ OWASP AGHAST→ Semgrep→ Cursor→ Claude Code→ SARIF→ NDC Security→ Black Hat→ DEF CON→ ISACA→ Manicode SecurityFollow the Application Security Podcast:➜ Home➜ X➜ LinkedIn➜ YouTube➜ Instagram➜ FacebookChapters:00:00 Meet Josh Grossman01:11 Why Josh built AGHAST04:22 Will AI disrupt AppSec tooling?06:09 How AGHAST combines static analysis and AI08:48 Deterministic rules and pure AI checks10:23 Reducing SAST false positives11:49 Using SARIF from existing scanners12:46 Building AGHAST with Claude Code14:14 The product specification and human judgment17:48 How much code did the AI write?19:05 The architect and product-manager mindset21:08 Token economics becomes its own industry22:54 Authorization and business-logic checks25:55 Context makes custom rules valuable28:15 Where AGHAST belongs in the workflow30:11 Languages, frameworks, and COBOL32:10 The AGHAST roadmap34:20 Key takeaway and call to action36:56 Training and conference appearances37:29 AGHAST demonstration

Episode metadata supplied by the publisher feed · Published Jun 2, 2026

Embed this episode

Traditional SAST is deterministic but shallow; AI can reason about context but may answer differently every time. Can the two approaches make each other better? Bounce Security CTO Josh Grossman explains why he built AGHAST, an open-source framework that combines static discovery with LLM analysis to investigate authorization, business-logic, and organization-specific risks. He walks through reducing false positives, importing SARIF, controlling token costs, and deciding where AI-assisted che...

Distinct summary based on available episode metadata or transcript content.

Ready to play

Josh Grossman--AI & SAST: Is it a match?

0:00 40:29

No transcript for this episode yet

We transcribe on demand. Request one and we'll notify you when it's ready — usually under 10 minutes.

No similar episodes found.

No similar podcasts found.

Frequently Asked Questions

How long is this episode of The Application Security Podcast?

This episode is 40 minutes long.

When was this The Application Security Podcast episode published?

This episode was published on June 2, 2026.

Can I download this The Application Security Podcast episode?

Yes. Use the download control on the episode player to save the publisher-provided media file.
URL copied to clipboard!