Skip to content
View mateofumis's full-sized avatar
🎯
Working on it
🎯
Working on it

Block or report mateofumis

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
mateofumis/README.md

Mateo Fumis

Security Researcher · Offensive Security Engineer

Application Security · Mobile Security · Android · Web & API Security

Website · LinkedIn · Research · Bugcrowd · Email


I am a Security Researcher and Offensive Security Engineer focused on application security, vulnerability research, and security tooling.

My work spans Web, API, and Mobile Application Security, with a particular focus on Android security, reverse engineering, dynamic instrumentation, and identifying vulnerabilities through both manual analysis and offensive security research.

I contribute to the OWASP Mobile Application Security (MAS) project and build open-source tools to support security testing and research workflows.

Selected Work

Static analysis tooling for Android application attack-surface discovery. Analyzes AndroidManifest.xml, identifies exposed application components, and assists with generating commands for security testing.

Reconnaissance tooling for automating advanced search queries during security research and vulnerability discovery.

Command-line tooling for simplifying the setup and management of Frida Server and Frida Gadget in Android dynamic instrumentation environments.

Reproducible Docker-based environment for Android security testing, integrating tools such as Frida, Objection, and ADB.

Research & Writing

I publish technical research and notes covering topics such as:

  • Android application security
  • Mobile reverse engineering
  • WebView and deep-link attack surfaces
  • Android IPC and exposed components
  • Web and API security
  • Vulnerability research
  • Offensive security tooling

Research: mfumis.com
Knowledge Base: Offensive Cybersecurity by hackermater

Contact

For security research, open-source collaboration, or professional inquiries:

Website: mfumis.com
LinkedIn: Mateo Gabriel Fumis
Email: contact@mfumis.com
Bugcrowd: hackermater


Security research published as hackermater.

Pinned Loading

  1. dumpdork dumpdork Public

    Search-driven OSINT and reconnaissance toolkit for web and GitHub discovery.

    Python 41 6

  2. fridaDownloader fridaDownloader Public

    fridaDownloader is a command-line tool that streamlines downloading the Frida Gadget or Server for Android, enabling developers and security researchers to quickly access the components needed for …

    Python 3 2

  3. AndroidManifestExplorer AndroidManifestExplorer Public

    A professional tool to automate attack surface detection in Android applications by parsing Manifest files.

    Python 16 3

  4. mobile-pentesting-setup mobile-pentesting-setup Public

    All-in-one simple setup for optimal android pentesting using tools such as Frida, Objection, etc...

    Dockerfile 1

  5. SEPunycoder.py SEPunycoder.py Public

    A simple script to convert normal-text to Cyrillic-text. This allows hackers to obfuscate text in puny-code format which can lead into a lot of multiple Phishing attacks.

    Python 2

  6. OWASP/mastg OWASP/mastg Public

    The OWASP Mobile Application Security Testing Guide (MASTG) is a comprehensive manual for mobile app security testing and reverse engineering. It describes technical processes for verifying the OWA…

    Python 13.2k 2.8k