Security Researcher · Offensive Security Engineer
Application Security · Mobile Security · Android · Web & API Security
Website · LinkedIn · Research · Bugcrowd · Email
I am a Security Researcher and Offensive Security Engineer focused on application security, vulnerability research, and security tooling.
My work spans Web, API, and Mobile Application Security, with a particular focus on Android security, reverse engineering, dynamic instrumentation, and identifying vulnerabilities through both manual analysis and offensive security research.
I contribute to the OWASP Mobile Application Security (MAS) project and build open-source tools to support security testing and research workflows.
Static analysis tooling for Android application attack-surface discovery. Analyzes AndroidManifest.xml, identifies exposed application components, and assists with generating commands for security testing.
Reconnaissance tooling for automating advanced search queries during security research and vulnerability discovery.
Command-line tooling for simplifying the setup and management of Frida Server and Frida Gadget in Android dynamic instrumentation environments.
Reproducible Docker-based environment for Android security testing, integrating tools such as Frida, Objection, and ADB.
I publish technical research and notes covering topics such as:
- Android application security
- Mobile reverse engineering
- WebView and deep-link attack surfaces
- Android IPC and exposed components
- Web and API security
- Vulnerability research
- Offensive security tooling
Research: mfumis.com
Knowledge Base: Offensive Cybersecurity by hackermater
For security research, open-source collaboration, or professional inquiries:
Website: mfumis.com
LinkedIn: Mateo Gabriel Fumis
Email: contact@mfumis.com
Bugcrowd: hackermater
Security research published as hackermater.
