Sign in

Josh Grossman (tghosth 👻)

@joshcgrossman.com
1.3K followers 432 following 182 posts

Friendly AppSec Ghost 👻 appsecg.host

PostsRepliesMedia
Josh Grossman (tghosth 👻) @joshcgrossman.com · 08/06/2026
Introducing, the new Secure Software Development Lifecycle!!!!!
042
Josh Grossman (tghosth 👻) @joshcgrossman.com · 20/05/2026
This makes aghast a much better fit for CI pipelines where you want fast, targeted feedback on every PR without sacrificing depth. 🔍 --- 📦 npm install -g @bouncesecurity/aghast@0.7.1 4/4
010
Josh Grossman (tghosth 👻) @joshcgrossman.com · 20/05/2026
🕸️ When OpenAnt is available, filtering is call-graph-aware catching not just lines you changed, but functions that call or are called by the changed code. When OpenAnt isn't around, it gracefully falls back to file+line overlap with a clear warning. 3/4
100
Josh Grossman (tghosth 👻) @joshcgrossman.com · 20/05/2026
How? 🎯 Pass --diff-ref, --diff-file, or AGHAST_DIFF_REF and aghast automatically narrows all discovery results (Semgrep, SARIF, OpenAnt) to findings that touch your diff. 2/4
100
Josh Grossman (tghosth 👻) @joshcgrossman.com · 20/05/2026
🚀 Introducing aghast v0.7.1: Diff-scoped security scanning When you're reviewing a PR, you don't want to be flooded with findings from code that didn't change. v0.7.1 adds automatic diff filtering so aghast focuses its analysis on what actually changed. 1/4
100
Josh Grossman (tghosth 👻) @joshcgrossman.com · 18/05/2026
Them: We need a super-sophisticated AI powered security review tool to stop vulnerabilities entering our products. Me: No, you just need to stop ignoring the security PR comments that your current AI reviewer is adding...
000
Josh Grossman (tghosth 👻) @joshcgrossman.com · 14/05/2026
Live footage of anyone trying to do anything clever using the @ClaudeDevs AgentSDK 🤦‍♂️🤦‍♂️🤦‍♂️ #Anthropic #BaitAndSwitcha #Claude
000
Reposted by Josh Grossman (tghosth 👻)
OWASP Juice Shop @owasp-juice.shop · 13/05/2026
OWASP Juice Shop v20 is here! 🍹 Featuring: AI/LLM-based chatbot (w/ 3 hacking + 2 coding challenges), redesigned storefront, ~30% faster startup time, Angular 21, neon-fire & lime-green theme, and much more! owasp.org/blog/2026/05...
12113
Josh Grossman (tghosth 👻) @joshcgrossman.com · 12/05/2026
Quiz! I submitted an Open Source Program application to @AnthropicAI to assist with my work on @OWASP_ASVS. (Don't quite meet requirements but thought I'd try) Did I get: a) Accepted onto the program b) No response c) Spam to the email address I used to register d) both b + c?
000
Josh Grossman (tghosth 👻) @joshcgrossman.com · 10/05/2026
Having spent a bunch of time using Opus, I tried to economize last week by using Sonnet more. I feel like it makes more mistakes and needs more guidance, even if I get Opus to plan first. Starting to wonder whether the time incurred costs more than the token saving...
000
Josh Grossman (tghosth 👻) @joshcgrossman.com · 07/05/2026
🚀 aghast v0.6.0 is out! Cost and budget controls, per-check repository exclusion, and enhanced security hardening. Run aghast stats to see your scan costs, set budgets, and scale with confidence. Get it: npm install -g @bouncesecurity/aghast #SecurityTesting #DevSecOps
010
Josh Grossman (tghosth 👻) @joshcgrossman.com · 05/05/2026
Wearing my @Semgrep socks to celebrate as sorting by name finally comes to the Semgrep playground. Thanks Semgrep Hack Week!!!
000
Josh Grossman (tghosth 👻) @joshcgrossman.com · 04/05/2026
I recorded a series of videos demonstrating different ways in which you can use #AGHAST. This is the 5th example where we take the units produced by a @Knostic OpenAnt scan and scan those units individually for vulnerabilities.
youtu.be
AGHAST - Walkthrough of Example 5
This video walks you through example 5 from the AGHAST documentation. Link to the explanation of this example: https://github.com/BounceSecurity/aghast/blob/main/docs/trying-it-out.md#example-5-various-security-vulnerabilities-targeted-check-openant-discovery-general-vulnerability-analysis Link to
000
Josh Grossman (tghosth 👻) @joshcgrossman.com · 30/04/2026
I recorded a series of videos demonstrating different ways in which you can use #AGHAST. This 4th example takes a SARIF file simulating some generic SAST results and evaluates each finding to decide if it is a false positive.
youtu.be
AGHAST - Walkthrough of Example 4
This video walks you through example 4 from the AGHAST documentation. Link to the explanation of this example: https://github.com/BounceSecurity/aghast/blob/main/docs/trying-it-out.md#example-4-sast-finding-verification-targeted-check-sarif-input-false-positive-validation Link to the repository of
000
Josh Grossman (tghosth 👻) @joshcgrossman.com · 28/04/2026
I recorded a series of videos demonstrating different ways in which you can use #AGHAST. This is the 3rd example which doesn't use AI at all but rather just a custom written static rule to find exposed API endpoints without authentication decorators.
youtu.be
AGHAST - Walkthrough of Example 3
This video walks you through example 3 from the AGHAST documentation. Link to the explanation of this example: https://github.com/BounceSecurity/aghast/blob/main/docs/trying-it-out.md#example-3-missing-api-token-decorator-static-check-semgrep-discovery Link to the repository of public examples: ht
000
Josh Grossman (tghosth 👻) @joshcgrossman.com · 27/04/2026
I recorded a series of videos demonstrating different ways in which you can use #AGHAST. This 2nd video is a hybrid check using a static @Semgrep rule to find uses of a sensitive function and an AI prompt on each use to check for correct validation.
youtu.be
AGHAST - Walkthrough of Example 2
This video walks you through example 2 from the AGHAST documentation. Link to the explanation of this example: https://github.com/BounceSecurity/aghast/blob/main/docs/trying-it-out.md#example-2-important-validations-before-ai-queries-targeted-check-semgrep-discovery Link to the repository of publi
000
Josh Grossman (tghosth 👻) @joshcgrossman.com · 27/04/2026
I recorded a series of videos demonstrating different ways in which you can use #AGHAST. This is the 5th example where we take the units produced by a @Knostic OpenAnt scan and scan those units individually for vulnerabilities.
youtu.be
AGHAST - Walkthrough of Example 5
This video walks you through example 5 from the AGHAST documentation. Link to the explanation of this example: https://github.com/BounceSecurity/aghast/blob/main/docs/trying-it-out.md#example-5-various-security-vulnerabilities-targeted-check-openant-discovery-general-vulnerability-analysis Link to
000
Josh Grossman (tghosth 👻) @joshcgrossman.com · 26/04/2026
I recorded a series of videos demonstrating different ways in which you can use #AGHAST. This is the first one with a simple check that just uses an AI prompt to look for business logic being incorrectly enforced.
youtu.be
AGHAST - Walkthrough of Example 1
This video walks you through example 1 from the AGHAST documentation. Link to the explanation of this example: https://github.com/BounceSecurity/aghast/blob/main/docs/trying-it-out.md#example-1-business-logic-bypass-repository-check Link to the repository of public examples: https://github.com/Bou
000
Josh Grossman (tghosth 👻) @joshcgrossman.com · 23/04/2026
I recorded a series of videos demonstrating different ways in which you can use #AGHAST. This 4th example takes a SARIF file simulating some generic SAST results and evaluates each finding to decide if it is a false positive.
youtu.be
AGHAST - Walkthrough of Example 4
This video walks you through example 4 from the AGHAST documentation. Link to the explanation of this example: https://github.com/BounceSecurity/aghast/blob/main/docs/trying-it-out.md#example-4-sast-finding-verification-targeted-check-sarif-input-false-positive-validation Link to the repository of
000
Josh Grossman (tghosth 👻) @joshcgrossman.com · 21/04/2026
I recorded a series of videos demonstrating different ways in which you can use #AGHAST. This is the 3rd example which doesn't use AI at all but rather just a custom written static rule to find exposed API endpoints without authentication decorators.
youtu.be
AGHAST - Walkthrough of Example 3
This video walks you through example 3 from the AGHAST documentation. Link to the explanation of this example: https://github.com/BounceSecurity/aghast/blob/main/docs/trying-it-out.md#example-3-missing-api-token-decorator-static-check-semgrep-discovery Link to the repository of public examples: ht
000
Josh Grossman (tghosth 👻) @joshcgrossman.com · 20/04/2026
I recorded a series of videos demonstrating different ways in which you can use #AGHAST. This 2nd video is a hybrid check using a static @Semgrep rule to find uses of a sensitive function and an AI prompt on each use to check for correct validation.
youtu.be
AGHAST - Walkthrough of Example 2
This video walks you through example 2 from the AGHAST documentation. Link to the explanation of this example: https://github.com/BounceSecurity/aghast/blob/main/docs/trying-it-out.md#example-2-important-validations-before-ai-queries-targeted-check-semgrep-discovery Link to the repository of publi
000
Josh Grossman (tghosth 👻) @joshcgrossman.com · 16/04/2026
I recorded a series of videos demonstrating different ways in which you can use #AGHAST. There is the first one with a simple check that just uses an AI prompt to look for business logic being incorrectly enforced.
youtu.be
AGHAST - Walkthrough of Example 1
This video walks you through example 1 from the AGHAST documentation. Link to the explanation of this example: https://github.com/BounceSecurity/aghast/blob/main/docs/trying-it-out.md#example-1-business-logic-bypass-repository-check Link to the repository of public examples: https://github.com/Bou
000
Josh Grossman (tghosth 👻) @joshcgrossman.com · 14/04/2026
Get started and learn more: 📖 Read the blog: www.bouncesecurity.c... 💻 Explore the code: github.com/BounceSec... 📦 Install via npm: www.npmjs.com/packag... 💡Examples: github.com/BounceSec... 📽️Videos: www.youtube.com/play... 4/4
bouncesecurity.com
Introducing AGHAST: AI-Guided Hybrid Application Static Testing | Bounce Security
tl;dr
000
Josh Grossman (tghosth 👻) @joshcgrossman.com · 14/04/2026
What it will do is give you a framework to take your suspicions about what vulnerabilities might exist and turn them into repeatable, scalable, and automatable validations you can run across your codebases, returning results in a structured format. 3/4
100
Josh Grossman (tghosth 👻) @joshcgrossman.com · 14/04/2026
AGHAST (AI-Guided Hybrid Application Static Testing) won't automatically scan your repositories and find all your vulnerabilities. 2/4
100
Josh Grossman (tghosth 👻) @joshcgrossman.com · 14/04/2026
Today, we are releasing AGHAST, an open source framework that combines static discovery with AI prompts to find repository-specific and company-specific security issues for accurate and economical analysis. 1/4
100
Josh Grossman (tghosth 👻) @joshcgrossman.com · 06/04/2026
I think my local, multi git account setup has reached its final form (for now...), starting Microsoft Windows, 1Password and some help from Claude :) Check out details here:
joshcgrossman.com
Getting multiple GitHub accounts on one Windows machine – 2026 update
A guide on how to manage multiple GitHub accounts on a single Windows machine using 1Password and SSH host aliases, updated for 2026.
010
Josh Grossman (tghosth 👻) @joshcgrossman.com · 30/03/2026
I think my local, multi git account setup has reached its final form (for now...), starting Microsoft Windows, 1Password and some help from Claude :) Check out details here:
joshcgrossman.com
Getting multiple GitHub accounts on one Windows machine – 2026 update
A guide on how to manage multiple GitHub accounts on a single Windows machine using 1Password and SSH host aliases, updated for 2026.
010
Josh Grossman (tghosth 👻) @joshcgrossman.com · 23/03/2026
Be the first to attend my new training course at @OWASP Global AppSec Vienna! "Repeatable, Scalable and Valuable Code Security Scanning" is a deep dive into the newest ways to validate code security with a strong emphasis on AI acceleration. Register: owaspglobalappseceuv...
000
Josh Grossman (tghosth 👻) @joshcgrossman.com · 16/03/2026
Be the first to attend my new training course at @OWASP Global AppSec Vienna! "Repeatable, Scalable and Valuable Code Security Scanning" is a deep dive into the newest ways to validate code security with a strong emphasis on AI acceleration. Register: owaspglobalappseceuv...
000
Josh Grossman (tghosth 👻) @joshcgrossman.com · 16/02/2026
I'm sure this blogpost will be interesting to the two or three other people people in the world who are using Claude Code on Windows and want to have multiple accounts active :) Keen to hear feedback and experiences 😀
joshcgrossman.com
Running two Claude Code accounts on one Windows PC (without them fighting)
How I isolated Personal and Work Claude Code accounts on a single Windows machine by faking per-account home directories and a handful of symlinks.
030
Josh Grossman (tghosth 👻) @joshcgrossman.com · 09/02/2026
I'm sure this blogpost will be interesting to the two or three other people people in the world who are using Claude Code on Windows and want to have multiple accounts active :) Keen to hear feedback and experiences 😀
joshcgrossman.com
Running two Claude Code accounts on one Windows PC (without them fighting)
How I isolated Personal and Work Claude Code accounts on a single Windows machine by faking per-account home directories and a handful of symlinks.
020
Josh Grossman (tghosth 👻) @joshcgrossman.com · 05/01/2026
Starting off the year with the uno reverse card 🤣🤣🤣
000
Josh Grossman (tghosth 👻) @joshcgrossman.com · 01/12/2025
Register: owasp.glueup.com/eve... More details: owasp.glueup.com/eve... www.bouncesecurity.c...
owasp.glueup.com
Registration ⇽ London OWASP Training Days 2026 | The OWASP Foundation Inc.
Register for "London OWASP Training Days 2026" hosted by OWASP Foundation Inc.
000
Josh Grossman (tghosth 👻) @joshcgrossman.com · 01/12/2025
LONDON, BABY! I'm bringing my course "Building a High-Value AppSec Scanning Programme" to London as part of @OWASP's London training days, 23-24 February 2026. As seen at OWASP Global conferences, @BlackHatEvents and @NDC_Conferences, don't miss your chance to attend!
100
Josh Grossman (tghosth 👻) @joshcgrossman.com · 11/11/2025
#justaithings
000
Josh Grossman (tghosth 👻) @joshcgrossman.com · 04/11/2025
CFTs for both @BlackHatEvents #BHUSA and @OWASP Global AppSec EU (Vienna) are now open and close in early December! Thinking of submitting? Check out my blog series for @BounceSecurity "So you want to train at Black Hat (or other conferences)?"
bouncesecurity.com
So, you want to train at Black Hat (or other conferences)? An Introduction | Bounce Security
Efficient, Value-Driven Product Security
000
Josh Grossman (tghosth 👻) @joshcgrossman.com · 02/09/2025
If you attended my vibe coding session at the @OWASP Community at @defcon (or you didn't but you are interested) and you want to continue the conversation, Emile Delcourt opened a dedicated channel on the @OWASP slack workspace: owasp.slack.com/arch...
011
Josh Grossman (tghosth 👻) @joshcgrossman.com · 11/08/2025
I can't bring myself to tag everyone but thanks to everyone I met and chatted to, every one of you enhanced the experience. For those of you working as volunteers and organisers, you are the ones who make all of this happen and you have my undying respect and appreciation!
000
Josh Grossman (tghosth 👻) @joshcgrossman.com · 11/08/2025
4) Getting to switch things down a gear at the annual one-of-a-kind ShabbatCon with great conversations and the famous "no-fire" talks. 5) Crazy golf at the Chainguard/Orca party with Avi and Kim, I do love crazy golf!
110
Josh Grossman (tghosth 👻) @joshcgrossman.com · 11/08/2025
3a) Volunteering for the OWASP Community space at DEFCON to talk to people about the foundation and collect donations in exchange for t-shirts. 3b) Delivering a "What is OWASP" talk for the community space as well as leading a packed discussion about AppSec and vibe coding.
100
Josh Grossman (tghosth 👻) @joshcgrossman.com · 11/08/2025
1) Delivering another round of my training course about accelerating your AppSec programme. 2) Meeting loads of people at Black Hat, some intentionally and some by happy coincidence and building connections.
100
Josh Grossman (tghosth 👻) @joshcgrossman.com · 11/08/2025
About to head home after a packed week+ in Vegas for Hacker Summer Camp. Some highlights for me:
100
Josh Grossman (tghosth 👻) @joshcgrossman.com · 06/08/2025
My point is not the content but rather the skillset.If I as a security person don't have those skills then people are going to listen to someone who does
210
Josh Grossman (tghosth 👻) @joshcgrossman.com · 06/08/2025
My searing hot take for today is that everyone hitting out at "security influencer" culture might want to consider that being able to persuade and influence is probably the most important tool in your security skillset.
100
Josh Grossman (tghosth 👻) @joshcgrossman.com · 05/08/2025
Excited to be back delivering my course again at Black Hat USA!
120
Josh Grossman (tghosth 👻) @joshcgrossman.com · 17/07/2025
In "Making your preparations" I discuss some of the preparations you might need in the run-up to the course including materials and visa considerations. Although visas are one of the last things I mention, it might be one of the first things to consider. www.bouncesecurity.c...
bouncesecurity.com
Making your preparations | Bounce Security
Introduction
010
Josh Grossman (tghosth 👻) @joshcgrossman.com · 17/07/2025
In "Selling and Marketing your course", I talk about possibly the hardest part of the whole process, getting people to sign-up! I don't have all the answers but hopefully I have some ideas and thoughts that will be useful to you. www.bouncesecurity.c...
bouncesecurity.com
Selling and Marketing your course | Bounce Security
Introduction
110
Josh Grossman (tghosth 👻) @joshcgrossman.com · 17/07/2025
The final two parts of my blog series about delivering training at conferences have now been released! You can check them out on the @BounceSecurity website now!
121
Josh Grossman (tghosth 👻) @joshcgrossman.com · 02/07/2025
Most passkey implementations are tripping over themselves to fall back to sending you an email OTP as fast as possible... Passkeys are for UX, not for security
000