The Application Security Podcast

The Future of Open-Source Threat Modeling

Chris Romeo and Robert Hurlbut Season 13 Episode 8

Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.

0:00 | 40:14

You don't have to let AI do the thinking for you. In this episode, Vikram Narayan shares why the smartest teams use AI as an accelerant — not a replacement — and why human judgment still matters most in threat modeling. Vikram created Precogly, an open-source threat modeling platform now running as an OWASP project, and he walks us through what it took to build a free tool on par with commercial vendors. We dig into the tension among speed, compliance, and real risk; whether the Threat Modeling Manifesto needs amending for AI; and what it means to "fight the AI" so critical thinking stays sharp. If you care about AppSec, AI, and the future of threat modeling, this conversation will give you a lot to think about.

This episode is sponsored by Corgea. Design it. Build it. Ship it. Corgea secures it.

About Corgea
Corgea is an AI-native application security platform that secures software from design to production. It brings together security design reviews, AI SAST, dependency and IaC scanning, code quality checks, and autonomous pentesting—helping security and engineering teams find risk earlier, fix what matters, and ship securely.
Learn more about Corgea

Connect with Vikram Narayan:
Vikram Narayan on LinkedIn
Precogly — open-source threat modeling (OWASP project)

Mentioned in this episode:
Threat Modeling Manifesto
ThreatModCon

Follow the Application Security Podcast:
➜ Home: appsecpodcast.com
➜ X: @AppSecPodcast
➜ LinkedIn: The Application Security Podcast
➜ YouTube: @ApplicationSecurityPodcast
➜ Instagram: @appsecpodcast
➜ Facebook: Application Security Podcast

Chapters:
00:00 Cold open — the threat model that "feels wrong"
01:22 Welcome and introductions
02:17 Vikram's security origin story
05:43 From machine learning research into LLMs
06:42 Hospital chatbots, hallucination, and knowing when to escalate
07:51 ThreatModCon and the case for an open-source threat modeling tool
09:35 IoT, emergence, and the traffic-light problem
11:17 The OWASP Vienna talk and the Threat Modeling Manifesto
12:26 Why "AI, just do the threat model" falls apart
15:14 What AI is actually good at in threat modeling
18:07 Human discomfort vs. the machine's confident answer
20:29 Inside Precogly: accelerant, not replacement
20:58 Library packs and the skills layer
24:50 Where AI kicks in — and where it shouldn't
27:48 Should the Threat Modeling Manifesto be amended for AI?
30:28 Where Chris and Robert land
31:36 Wi-Fi sensing, privacy, and modeling what you can't see
33:15 If you can't explain it, can you trust it?
35:11 Beyond checklists — design-level questions
35:59 Fight the AI — Vikram's key takeaway
39:10 Closing thoughts

Follow the Application Security Podcast:

➜ Home: appsecpodcast.com
➜ X: @AppSecPodcast
➜ LinkedIn: The Application Security Podcast
➜ YouTube: @ApplicationSecurityPodcast
➜ Instagram: @appsecpodcast
➜ Facebook: Application Security Podcast

People on this episode

Podcasts we love

Check out these other fine podcasts recommended by us, not an algorithm.

The Security Table Artwork

The Security Table

Izar Tarandach, Matt Coles, and Chris Romeo