# Using LLMs to help lead threat modeling sessions

**URL:** <https://threatmodelingconnect.discourse.group/t/using-llms-to-help-lead-threat-modeling-sessions/88>\
**Category:** Techniques & Tooling\
**Created:** [July 5, 2023, 7:00am UTC](https://threatmodelingconnect.discourse.group/t/using-llms-to-help-lead-threat-modeling-sessions/88 "2023-07-05T07:00:00Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![community\_migration](https://sea2.discourse-cdn.com/flex002/user_avatar/threatmodelingconnect.discourse.group/community_migration/32/366_2.png) [@community\_migration](https://threatmodelingconnect.discourse.group/u/community_migration)\
**Post date:** [July 5, 2023, 7:00am UTC](https://threatmodelingconnect.discourse.group/t/using-llms-to-help-lead-threat-modeling-sessions/88/1 "2023-07-05T07:00:00Z")

</div>

Original post by @madchap

Hey all,

I have not seen any posts nor much out there… but I am sure some people are thinking about this right? With the right DFD metadata and possibly a gherkin-like way to describe scenarios, it feels like something could be done.

What are the collective thoughts around using AI to help lead threat modeling sessions to scale appsec teams efforts? Is there something out there that’s already midly useful?

If I knew what I was doing, that’s probably something I’d start thinking on building 🙂

Cheers,

---

<div class="post-metadata">

**Author:** ![community\_migration](https://sea2.discourse-cdn.com/flex002/user_avatar/threatmodelingconnect.discourse.group/community_migration/32/366_2.png) [@community\_migration](https://threatmodelingconnect.discourse.group/u/community_migration)\
**Post date:** [July 5, 2023, 7:00am UTC](https://threatmodelingconnect.discourse.group/t/using-llms-to-help-lead-threat-modeling-sessions/88/2 "2023-07-05T07:00:27Z")

</div>

_Original post by @cramirez_

It’s definitely been something that’s been discussed. Back in April, there was a webinar between Adam Shostack and Gary McGraw on this very subject - When will Adam Shostack be replaced by ChatGPT? ([https://www.youtube.com/watch?v=9k3scZFKYYA](https://www.youtube.com/watch?v=9k3scZFKYYA)). We’re frequently discussing AI (almost daily) and the different potential use cases (and risks) at work.

As for actual tools available, I’m not currently aware of any for LLM threat modeling….yet. Most of what I’ve seen lately is around attack tools (e.g. BurpGPT, PentestGPT, etc).

---

<div class="post-metadata">

**Author:** ![community\_migration](https://sea2.discourse-cdn.com/flex002/user_avatar/threatmodelingconnect.discourse.group/community_migration/32/366_2.png) [@community\_migration](https://threatmodelingconnect.discourse.group/u/community_migration)\
**Post date:** [July 5, 2023, 7:00am UTC](https://threatmodelingconnect.discourse.group/t/using-llms-to-help-lead-threat-modeling-sessions/88/3 "2023-07-05T07:00:57Z")

</div>

_Original post by @amitpaz_

Well,  
It’s possible to use founditional models for threat modelling purpose (i’m using it)  
You just need to set the expectations on which phases would require what kind of training and tuning

I’ll be happy to disclose more if my paper gets accepted

---

<div class="post-metadata">

**Author:** ![community\_migration](https://sea2.discourse-cdn.com/flex002/user_avatar/threatmodelingconnect.discourse.group/community_migration/32/366_2.png) [@community\_migration](https://threatmodelingconnect.discourse.group/u/community_migration)\
**Post date:** [July 5, 2023, 7:01am UTC](https://threatmodelingconnect.discourse.group/t/using-llms-to-help-lead-threat-modeling-sessions/88/4 "2023-07-05T07:01:20Z")

</div>

_Original post by @MartinPeters_

Hi, if you’re searching for a method similar to the Gherkin syntax for describing scenarios, you might find this resource helpful: **[A Tool to Help Improve Your Threat Modeling](https://d1.awsstatic.com/events/Summits/awsreinforce2023/APS224_A-tool-to-help-improve-your-threat-modeling.pdf) (Threat composer from AWS)**. Please refer to slide 16 and onwards for more information
