Fork and Knife: How AI Threat Modeling and Adversarial Testing Finally Close the Loop

Fork and Knife: How AI Threat Modeling and Adversarial Testing Finally Close the Loop

A threat model is a hypothesis. It says: here’s what could go wrong, here’s how bad it would be, here’s what to fix first. What it doesn’t do, on its own, is tell you whether any of it is actually true in production. That gap — between the model and the proof — is where most AppSec programs quietly lose their credibility.

Fork and Knife are built to close it. Fork is VerSprite’s continuous application threat modeling platform, built on PASTA and accelerated by AI. Knife is the AI-led, human-on-the-loop adversarial testing platform that validates what Fork surfaces. Used together, they turn threat modeling from a static document into a system that models, tests, and updates itself as an application changes.




Why AI Threat Modeling Needs More Than STRIDE

For most of the last two decades, threat modeling has run on STRIDE — spoofing, tampering, repudiation, information disclosure, denial of service, elevation of privilege. STRIDE is a useful vocabulary for sorting threats into buckets. It has never been a methodology. It doesn’t ingest live threat intelligence, doesn’t weigh business impact, and has nothing to say about the adversary behaviors that actually drive risk today: persistence, extortion, supply-chain compromise, and the new attack surface that AI-enabled applications introduce.

The practical result is familiar to anyone who’s run a security program: threat modeling becomes a one-time, document-heavy exercise. It lands late in the development lifecycle, goes stale the moment the application changes, and rarely connects to the testing that would confirm whether any of it holds up. Meanwhile, the applications keep shipping. The gap between how fast software moves and how slowly it gets modeled has become a real source of exposure — and AI threat modeling only earns the name if it closes that gap, not just automates the paperwork.




What Fork Does

Fork is a software-driven implementation of PASTA — the risk-centric, business-aligned threat modeling methodology VerSprite founder and CEO Tony UcedaVélez co-authored. PASTA’s seven stages move from business objectives through technical scope, application decomposition, threat analysis, vulnerability and weakness analysis, attack modeling, and risk and impact analysis, so the threats that surface are the ones most likely to occur and most costly if they do.

Fork brings that structure to sprint speed rather than audit speed. A few things it does specifically:

  • Trims the attack tree with AI. Instead of an exhaustive, theoretical list of everything that could happen, Fork’s AI narrows the tree to viable, high-impact paths analysts should actually spend time on.
  • Contextualizes every model. Fork enriches models with live threat intelligence, current vulnerability data across the full technology stack, and attack vectors substantiated by real adversarial testing — not just theoretical ones.
  • Maps to the frameworks security teams already report against. Findings correlate automatically to CWE, CVE with EPSS scoring, CAPEC, ATT&CK, D3FEND, and ASVS, so mitigations are defensible in the language leadership and auditors already use.
  • Recalculates residual risk continuously. As tests complete and conditions change, a proprietary risk formula updates so the model reflects current exposure, not exposure as of the last workshop.
  • Gives every stakeholder one view. Security, engineering, product, and business see the same picture of the attack surface, the threat landscape, and what’s been done about it.

The result: a defensible, risk-prioritized threat model in under two hours, kept current from sprint one rather than assembled once and shelved.




What Knife Does

A threat model is only as good as its assumptions. Knife exists to test them. It’s an AI-led, human-on-the-loop adversarial platform for web applications and web API endpoints, trained on more than two decades of offensive security work from VerSprite’s BREAKERS team. Where Fork defines which attack paths matter most, Knife proves — or disproves — them, pairing AI’s speed with expert human oversight so findings hold up to real-world scrutiny.




How Fork and Knife Work Together

This is the part that actually changes the operating model. From inside a Fork threat model, a team can request targeted, on-demand testing of a specific weakness or attack pattern. Knife runs the assessment. Results flow back into the model automatically, and Fork recalculates residual risk on the spot.

That closes a loop that’s been broken in AppSec for years: threat modeling and testing happening as two disconnected events, often run by different teams on different timelines, with no mechanism for one to inform the other in real time. With Fork and Knife integrated, modeling and testing become a continuous, self-updating system rather than a sequence of one-off deliverables.

Tony UcedaVélez has framed this as the next operating model for the discipline: STRIDE gave the industry a shared vocabulary for threats, and PASTA gave it a methodology for prioritizing them by risk. Fork and Knife are meant to give that methodology operational speed — continuous modeling and AI-led testing that move at the pace software actually ships, and at the pace adversaries actually operate.

 From inside a Fork threat model, a team can request targeted, on-demand testing of a specific weakness or attack pattern. Knife runs the assessment. Results flow back into the model automatically, and Fork recalculates residual risk on the spot.



Where Fork Fits Into an Existing Security Stack

Fork is designed to sit on top of the tooling security teams already run, not replace it. It integrates across SAST, DAST, software composition analysis, vulnerability scanning, cloud security posture management, attack surface management, penetration testing platforms, and IT service management — including connected and roadmapped integrations with ServiceNow, Veracode, Snyk, Semgrep, Checkmarx, OpenCTI, Qualys, Tenable, Mandiant, and Archer. Findings that used to live in scattered tools and separate reports get pulled into a single, living risk picture that updates as tests complete.




Getting Started

Fork ships in three tiers:

  • Fork Community — free, supporting a single application threat model with vulnerability ingestion via SBOM or OVAL.
  • Fork Enterprise — unlimited applications and teams, full integration access, SSO, granular access controls, and audit logging.
  • Fork Enterprise PT — adds on-demand adversarial testing powered by Knife and the BREAKERS team, requested directly from within a threat model.

VerSprite also offers Threat Modeling as a Service for organizations that want expert-led training or fully managed delivery.




FAQ

What is Fork?

Fork is VerSprite’s continuous application threat modeling platform, built on the PASTA methodology and accelerated by AI. It produces risk-centric threat models in under two hours and keeps them current as applications evolve.

What is Knife?

Knife is VerSprite’s AI-led, human-on-the-loop adversarial testing platform for web applications and web API endpoints, built on more than 20 years of offensive security work from VerSprite’s BREAKERS team.

How do Fork and Knife work together?

Teams request targeted testing of specific attack paths directly from within a Fork threat model. Knife runs the test, results feed back into the model, and Fork recalculates residual risk automatically — turning modeling and testing into one continuous process instead of two separate ones.

Is Fork free to use?

Yes. Fork Community is free and supports one application threat model with SBOM or OVAL vulnerability ingestion. Enterprise tiers add unlimited applications, integrations, and access to Knife-powered adversarial testing.

What methodology is Fork built on?

Fork implements PASTA (Process for Attack Simulation and Threat Analysis), the risk-centric threat modeling methodology co-authored by VerSprite founder Tony UcedaVélez.




Ready to see a risk-prioritized threat model in under two hours? Start free with Fork or request a demo.