spyros gasteratos

Spyros has over 15 years of experience in the security world. Since the beginning of his career he has been an avid supporter and contributor of open source software and an OWASP volunteer. Currently he is interested in the harmonization of security tools and information and is currently helping Fintechs setup and automate large parts of their AppSec programmes. He also maintains several Open Source projects including the security automation framework Smithy, and opencre.org, the worlds largest


Your twitter or other social network

https://www.linkedin.com/in/spyr/

Which country are you from?

UK


Session

10-18
15:00
50min
Smithy, the Open-Source SOAR You’d Actually Use
spyros gasteratos

Despite our collective efforts, we haven’t managed to harmonize security tools and processes. Several standards like NIST, ASVS, SAMM and others have attempted information harmony but few projects have attempted tool orchestration harmonization none in AppSec and for good reason, it is a hard problem to solve.

This session introduces Smithy, the only open-source workflow engine for security tools. Smithy stands as a unifying force for building robust, scalable DevSecOps, and beyond, pipelines. Leveraging Smithy’s support for OCSF-native data formats, we centralized the outputs of disparate security tools into a cohesive data lake, unlocking actionable insights that improved vulnerability prioritization and resource allocation.

The talk will showcase real-world applications, including integrating OpenCRE, Cartography, AI-driven solutions and open-source resources to enhance vulnerability detection accuracy and reprioritization, for free, using ready made community resources.

Whether you're a tech lead, security engineer, or CISO, this presentation offers practical guidance for creating adaptable, data-driven security workflows without breaking the bank.

Security Programs/Management
Track 2 (206a)