The Application Security Podcast
The Application Security Podcast is a practitioner-led show for anyone building or securing modern software—and now AI-powered applications. Hosts Chris Romeo and Robert Hurlbut talk with the people shaping application security about AI and LLM security, threat modeling, secure development, OWASP, cloud, DevSecOps, security champions, and building programs that help engineering teams move faster and safer. With more than 300 episodes, the show turns real-world experience into practical guidance for developers, architects, AppSec professionals, and security leaders.
The Application Security Podcast
Kristen Tan and Vaibhav Garg -- Machine Assisted Threat Modeling
Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.
Can machines make threat modeling faster without stripping away the judgment that makes it useful? Kristen Tan and Vaibhav Garg join Chris and Robert to discuss their analysis of open source automated threat modeling tools and what it reveals about automation, extensibility, security, and privacy. They explain why they studied the available tools, how they evaluated them, and where machine assistance can support rather than replace human reasoning. The conversation covers developer-friendly formats, privacy requirements, organizational fit, and the gap between generating threats and helping real working teams make better design decisions throughout the modern software development lifecycle in practice.
The Application Security Podcast is brought to you by Security Journey.
About Security Journey
Security Journey provides application security education for developers and everyone in the software development lifecycle.
→ Learn more about Security Journey
Connect with Kristen Tan and Vaibhav Garg:
→ Kristen Tan on LinkedIn
→ Vaibhav Garg on LinkedIn
Mentioned in this episode:
→ Analysis of open source automated threat modeling tools
→ OWASP pytm
Follow the Application Security Podcast:
➜ Home
➜ X
➜ LinkedIn
➜ YouTube
➜ Instagram
➜ Facebook
Chapters:
00:00 Machine-assisted threat modeling
01:44 Kristen Tan’s path to threat modeling research
03:29 Vaibhav Garg’s security and privacy background
06:49 Why analyze automated threat modeling tools
09:18 Security and privacy as connected disciplines
12:17 What motivated the research
14:37 Can machines automate threat modeling?
20:45 How the tools were evaluated
24:24 Open source tools and extensibility
28:59 Evaluation criteria and research results
35:14 Choosing a tool that fits the organization
37:00 YAML, developers, and usable workflows
39:00 Keeping threat modeling user-centered
45:00 Final takeaways
People on this episode
Podcasts we love
Check out these other fine podcasts recommended by us, not an algorithm.
The Security Table
Izar Tarandach, Matt Coles, and Chris Romeo