No video

Threat Modeling for Developers and Automation Tool by Izar Tarandach and Matthew Coles

  Рет қаралды 799

OWASP New York City Chapter

OWASP New York City Chapter

Күн бұрын

From our meetup on Thursday, February 11 2021: www.meetup.com...
Izar Tarandach (@izar_t) and Matthew Coles (@coles_matthewj) will discuss the following topics in applied threat modeling:
Principles: Formulate a conversation around the relationships of concepts in security. This will include attackers, exploits and value, and how the characteristics of these connections might be understood and managed.
Methods: Refresher on modeling techniques and things to consider, then dive into a selection of modeling and analysis methodologies that will help you get from principles to practice.
Evolution: Automated threat analysis using an open source tool(pytm). We will talk through the making of pytm and then do a demo.
*** Speaker bios
Izar Tarandach has peeked and poked at security from various sides over the last couple of decades, currently focusing on modern SDLC's and how AppSec extrapolates onto the larger scheme of Security. He has a MSc in Computer Science/Security from Boston U.
Matthew Coles (he/him) is a security professional focused on the security of physical devices and the ecosystems and processes that enable them to operate. He has an advanced degree in Computer Science from WPI, and maintains a CSSLP certification.
Izar and Matt have collaborated on security techniques and training for the past 10 years, co-authoring a book on Threat Modeling, and an open source threat modeling automation system, pytm.
- OWASP PyTM: owasp.org/www-...
- Threat Modeling Manifesto: www.threatmodel...
- Threat Modeling: A Practical Guide for Development Teams: www.amazon.com...
Appsec California 18/19/20 talks on CTM:
- • APPSEC Cali 2018 - The...
- • AppSecCali 2019 - Thre...
- • Scaling Up Is Hard To ...

Пікірлер
Using OWASP Nettacker For Recon and Vulnerability Scanning
59:15
OWASP New York City Chapter
Рет қаралды 153
I forced EVERYONE to use Linux
22:59
NetworkChuck
Рет қаралды 447 М.
Zombie Boy Saved My Life 💚
00:29
Alan Chikin Chow
Рет қаралды 20 МЛН
Кадр сыртындағы қызықтар | Келінжан
00:16
Мы сделали гигантские сухарики!  #большаяеда
00:44
Happy birthday to you by Tsuriki Show
00:12
Tsuriki Show
Рет қаралды 11 МЛН
Generative AI in a Nutshell - how to survive and thrive in the age of AI
17:57
What Is a Prompt Injection Attack?
10:57
IBM Technology
Рет қаралды 194 М.
Why is anti-immigration sentiment on the rise in Canada?
13:00
The Guardian
Рет қаралды 1,9 МЛН
Threat Modeling Lab | Security Threat Modeling Workshop
1:02:17
Threat Modeling Connect
Рет қаралды 347
Demystifying Application Security Posture Management (ASPM) - Payton O'Neal
21:26
OWASP New York City Chapter
Рет қаралды 250
“Is blockchain really secure??” by Shrutirupa Banerjiee
38:44
OWASP New York City Chapter
Рет қаралды 58
AI, Machine Learning, Deep Learning and Generative AI Explained
10:01
IBM Technology
Рет қаралды 100 М.
Do NOT Learn Kubernetes Without Knowing These Concepts...
13:01
Travis Media
Рет қаралды 273 М.
Zombie Boy Saved My Life 💚
00:29
Alan Chikin Chow
Рет қаралды 20 МЛН