EPISODE · Aug 17, 2026 · 40 MIN
The Future of Open-Source Threat Modeling
from The Application Security Podcast · host Chris Romeo and Robert Hurlbut
You don't have to let AI do the thinking for you. In this episode, Vikram Narayan shares why the smartest teams use AI as an accelerant — not a replacement — and why human judgment still matters most in threat modeling. Vikram created Precogly, an open-source threat modeling platform now running as an OWASP project, and he walks us through what it took to build a free tool on par with commercial vendors. We dig into the tension among speed, compliance, and real risk; whether the Threat Modeling Manifesto needs amending for AI; and what it means to "fight the AI" so critical thinking stays sharp. If you care about AppSec, AI, and the future of threat modeling, this conversation will give you a lot to think about.This episode is sponsored by Corgea. Design it. Build it. Ship it. Corgea secures it.About CorgeaCorgea is an AI-native application security platform that secures software from design to production. It brings together security design reviews, AI SAST, dependency and IaC scanning, code quality checks, and autonomous pentesting—helping security and engineering teams find risk earlier, fix what matters, and ship securely.→ Learn more about CorgeaConnect with Vikram Narayan:→ Vikram Narayan on LinkedIn→ Precogly — open-source threat modeling (OWASP project)Mentioned in this episode:→ Threat Modeling Manifesto→ ThreatModConFollow the Application Security Podcast:➜ Home: appsecpodcast.com➜ X: @AppSecPodcast➜ LinkedIn: The Application Security Podcast➜ YouTube: @ApplicationSecurityPodcast➜ Instagram: @appsecpodcast➜ Facebook: Application Security PodcastChapters:00:00 Cold open — the threat model that "feels wrong"01:22 Welcome and introductions02:17 Vikram's security origin story05:43 From machine learning research into LLMs06:42 Hospital chatbots, hallucination, and knowing when to escalate07:51 ThreatModCon and the case for an open-source threat modeling tool09:35 IoT, emergence, and the traffic-light problem11:17 The OWASP Vienna talk and the Threat Modeling Manifesto12:26 Why "AI, just do the threat model" falls apart15:14 What AI is actually good at in threat modeling18:07 Human discomfort vs. the machine's confident answer20:29 Inside Precogly: accelerant, not replacement20:58 Library packs and the skills layer24:50 Where AI kicks in — and where it shouldn't27:48 Should the Threat Modeling Manifesto be amended for AI?30:28 Where Chris and Robert land31:36 Wi-Fi sensing, privacy, and modeling what you can't see33:15 If you can't explain it, can you trust it?35:11 Beyond checklists — design-level questions35:59 Fight the AI — Vikram's key takeaway39:10 Closing thoughts
Embed this episode
What this episode covers
You don't have to let AI do the thinking for you. In this episode, Vikram Narayan shares why the smartest teams use AI as an accelerant — not a replacement — and why human judgment still matters most in threat modeling. Vikram created Precogly, an open-source threat modeling platform now running as an OWASP project, and he walks us through what it took to build a free tool on par with commercial vendors. We dig into the tension among speed, compliance, and real risk; whether the Threat Modeli...
Ready to play
The Future of Open-Source Threat Modeling
No transcript for this episode yet
Similar Episodes
No similar episodes found.
Similar Podcasts
No similar podcasts found.