Speaker

Mihir Shah

Mihir Shah

Security Engineering

Seattle, Washington, United States

Actions

Mihir Shah is a contributor in cloud-native and application and cloud security space. He is the author of the Cloud Native Software Security Handbook. As the leader of OWASP's VXDF Project, Mihir champions open-source solutions for automated threat modeling and vulnerability assessment. He spearheads initiatives in cloud and application security. Mihir regularly shares insights at Stanford University, global forums - OWASP conferences, community meetups, and Black Hat Dubai.

Area of Expertise

  • Information & Communications Technology

Topics

  • product security
  • Cloud Security
  • Cloud Native
  • Cloud Security Architecture
  • Cloud App Security
  • Application Security

OWASP VXDF: Is that really vulnerable? Show me the VXDF!

Every security professional and developer is buried under an avalanche of alerts from security scanners. The constant question is: "Is this finding a real, exploitable threat, or just another false positive?" This alert fatigue leads to wasted time, strained team relationships, and the increased risk that critical vulnerabilities are ignored. While the market is flooded with SAST, DAST, SCA tools, they only tell us what scanners found, they don't provide the definitive, evidence-backed proof needed to take immediate action.

This talk introduces Validated Exploitable Data Flow (VXDF), a new open-source standard designed to bridge the gap between a potential finding and a confirmed, actionable security bug. We will demonstrate how VXDF provides a structured, evidence-first narrative for each vulnerability, moving beyond scanner output to concrete proof. The core of this talk is a deep dive into VXDF's flagship evidence ingestion system, which supports over 30 distinct evidence types, focusing on OWASP Top 10 and other web vulnerabilities

Attendees will learn how to leverage the VXDF format and its reference engine to automate the correlation of scanner results with real-world proof, effectively eliminating false positives and providing developers with high-fidelity, trusted bug reports they can act on instantly.

OWASP Global AppSec USA 2025 - CFP (Washington, D.C) Sessionize Event Upcoming

November 2025 Washington, District of Columbia, United States

Mihir Shah

Security Engineering

Seattle, Washington, United States

Actions

Please note that Sessionize is not responsible for the accuracy or validity of the data provided by speakers. If you suspect this profile to be fake or spam, please let us know.

Jump to top