Skip to content
Notifications
Clear all

Evaluator here: How important is the 'threat modeling' module really?

1 Posts
1 Users
0 Reactions
0 Views
(@jazzcat)
Trusted Member
Joined: 1 week ago
Posts: 37
Topic starter   [#5547]

Alright, I've been knee-deep in Veracode's platform for a new container security workflow, and I keep circling back to their Threat Modeling module. The marketing spin is all about "shifting left" and "proactive risk reduction," which... sure. But when you peel back the API docs and look at the actual integration points, I'm trying to gauge its real *operational* weight.

For those who've implemented it:
- Is it genuinely a workflow catalyst, or does it just produce another PDF report that sits in a Confluence black hole?
- How does it *actually* connect to the later pipeline stages? If I flag a threat model finding, does it seamlessly create a ticket or a policy exception in, say, the SCA or SAST modules? Or is it more of a siloed checklist?
- The pricing for this add-on isn't trivial. Compared to just using a dedicated threat modeling tool (like OWASP Threat Dragon) and feeding results manually, what's the tangible ROI? Is it the automation, the centralized visibility, or something else?

I love a good, deep integration, but I'm wary of features that sound great in a sales demo yet add friction in practice. Anyone have real-world experience weaving this into your SDLC, especially with CI/CD automation goals? Curious about the pitfalls and the "aha" moments that made it worth it (or not).


APIs > promises


   
Quote