POA&M Automation Tool
Turns Nessus, Tenable, Qualys, and Wiz exports into FedRAMP-compliant POA&Ms. NIST 800-53 mapping, dedup, and live VDR reports with CISA KEV + EPSS lookups.
Offensive + Cloud Security
building Cloud Security _
Security analyst, hacker, and builder focused on FedRAMP, cloud security, and building tools that make compliance work less painful.
01 / workspace
Turns Nessus, Tenable, Qualys, and Wiz exports into FedRAMP-compliant POA&Ms. NIST 800-53 mapping, dedup, and live VDR reports with CISA KEV + EPSS lookups.
Multi-cloud evidence collector for AWS, Azure, and GCP. Covers 180+ resource types and 230+ automated checks mapped to NIST 800-53, packaged into audit-ready bundles.
Terminal CLI for CMMC 2.0 readiness. Gap assessment with SPRS scoring, SSP builder with multi-format export, and a searchable library of all 110 practices.
Local-first pentest and CTF notebook with AI help, Markdown editing, and exportable notes.
A demo trust center built for FedRAMP20x experimentation and practical learning.
Renames screenshots from visible text and image content, turning generic names into readable files like aws-vpc-route-tables.png.
Built with PDAs, wallet integration, and TypeScript tests.
Python desktop tool that auto-groups screenshots into session-based evidence folders.
Offline checklist app for FedRAMP and NIST 800-53 assessments with evidence tracking.
Local scanning tool for malware detection and audit-ready scan evidence.
02 / stack
03 / writeups
04 / credentials

CRTO

PNPT

School of Solana S8

eJPT

CySA+
05 / connect