About
A small firm that publishes its work.
Most security vendors ask you to trust a logo wall. This page is the alternative. Certifications you can verify, vulnerabilities you can look up in the National Vulnerability Database, and software you can go and use right now without talking to anyone.
What we do
Offensive work, and the compliance work that usually follows it.
Application, network and cloud testing, red and purple team engagements, and a parallel practice in defense contractor compliance: CMMC scoping, NIST SP 800-171 implementation, and the SSP and POA&M work that comes after. The two sides feed each other. A test that produces evidence an assessor accepts is worth more than either half on its own.
The eight free CMMC tools listed below are built and maintained in-house.
Led by Cody D. Martin, Partner, who holds:
- OSCP
- CRTP
- CARTP
- CAWASP
- PACSP
- CMMC-RP
Prior firms: Bishop Fox, Leviathan Security Group, Black Lantern Security, Synack Red Team, Cobalt
Published research
Eight CVEs, all verifiable
Found and disclosed at Black Lantern Security, not here, and credited to Cody personally in the National Vulnerability Database. They are listed because they are checkable evidence of the kind of work this firm does, not because APT Security Management discovered them. Every entry links to its NVD record.
| CVE | Product | Class |
|---|---|---|
| CVE-2021-27798 | Brocade Fabric OS | Privileged directory traversal |
| CVE-2021-27797 | Brocade Fabric OS | Weak default credentials |
| CVE-2021-27796 | Brocade Fabric OS | Privileged read |
| CVE-2020-27361 | Akkadian Provisioning Manager | Information disclosure |
| CVE-2020-26801 | Tripp Lite | Stored XSS |
| CVE-2020-16139 | Cisco Unified IP Conference Station 7937G | Denial of service |
| CVE-2020-16138 | Cisco Unified IP Conference Station 7937G | Denial of service |
| CVE-2020-16137 | Cisco Unified IP Conference Station 7937G | Privilege escalation |
Working software
Eight free CMMC tools, no signup
Built for defense contractors working through NIST SP 800-171 and the obligations that survived the July 2026 CMMC suspension. Free, no account, no email capture.
- CMMC Readiness Check
readiness-check.aptsecuritymanagement.com
- SPRS Score Calculator
sprs-calculator.aptsecuritymanagement.com
- CUI Identifier
cui-identifier.aptsecuritymanagement.com
- SSP Scaffolder
ssp-scaffolder.aptsecuritymanagement.com
- POA&M Builder
poam-builder.aptsecuritymanagement.com
- Practice Lookup
practice-lookup.aptsecuritymanagement.com
- Asset Categorizer
asset-categorizer.aptsecuritymanagement.com
- Flow-Down Letter Generator
flow-down-letter.aptsecuritymanagement.com
Standards work
Not just applying the standards. Helping write them.
Named in the contributor list of four App Defense Alliance specifications, covering mobile, cloud, and the testing procedure itself. Every one links to the document carrying the credit.
App Defense Alliance
MASA, the mobile application security assessment specification.
Read the specificationApp Defense Alliance
CASA, the cloud application security assessment specification.
Read the specificationApp Defense Alliance
The cloud application and configuration profile specification.
Read the specificationApp Defense Alliance
The MASA test guide, which is the testing procedure itself.
Read the specification
From a client
Seven Simple Machines
Published with their written permission, from an annual penetration testing engagement.
The APT team have been a pleasure to work with. They deliver clear, thorough reporting and make the remediation and retesting process smooth. Communication has been excellent throughout our engagement.
The APT team has consistently delivered excellent work and proven to be a trusted partner for our security goals. Their testing is rigorous, their communication is clear, and the experience across our team has been very positive.
Want to talk to the person who would do the work?
No SDR, no discovery call funnel. You get the practitioner.
