About me
Hi, I’m Mateo 👋
I’m an Application Security Engineer and Security Researcher focused on Mobile Application Security, Android, Web, and API security.
My work centers on manual vulnerability research, reverse engineering, offensive security testing, and developing practical tooling to improve security research workflows.
I actively contribute to the OWASP Mobile Application Security (MAS) Project and participate in vulnerability research and bug bounty programs through platforms such as Bugcrowd.
Through this blog, I publish technical research, vulnerability write-ups, tools, and lessons learned from real-world security work.
🔬 Areas of Focus
📱 Mobile AppSec
Android application security, static and dynamic analysis, reverse engineering, runtime instrumentation, and mobile API testing.
🔎 Security Research
Manual vulnerability research across mobile applications, web applications, APIs, and modern application environments.
🛠️ Open Source
Security tooling, automation, technical research, and contributions to the OWASP Mobile Application Security ecosystem.
🌐 Open Source & Community
I contribute to the OWASP Mobile Application Security (MAS) Project, helping improve resources used by mobile security engineers and researchers around the world.
I’m particularly interested in advancing practical methodologies for Android security testing, reverse engineering, vulnerability discovery, and offensive security automation.
I also publish my own tools, experiments, and research publicly whenever possible.
🏆 Credentials
eMAPT — Mobile Application Penetration Tester
The INE Security eMAPT is a hands-on certification focused on assessing and exploiting vulnerabilities in real-world Android and iOS applications.
Key areas include:
- Reconnaissance and Static Analysis
- Dynamic Testing and Runtime Manipulation
- API and Backend Security Testing
- Mobile Application Security Foundations
- Threat Modeling and Attacker Mindset
- Reverse Engineering and Code Deobfuscation
- Mobile Malware Analysis
- Reporting and Communication
Additional Training & Certifications
API Penetration Testing — APIsec University
Advanced API security testing covering reconnaissance, reverse engineering, Postman, BOLA, BFLA, JWT attacks, injections, SSRF, and the OWASP API Security Top 10.
Mobile Application Penetration Testing — TCM Security
Hands-on mobile application penetration testing using JADX, Apktool, Objection, Frida, Burp Suite, and Android Studio.
Practical API Hacking — TCM Security
API security testing covering endpoint discovery, fuzzing, authorization vulnerabilities, JWT attacks, HTTP method manipulation, and sensitive data exposure.
Practical Web Application Security and Testing — TCM Security
Web application security testing covering HTTP fundamentals, client/server architecture, OWASP ZAP, vulnerability discovery, and professional reporting.
Practical Ethical Hacking — TCM Security
Offensive security training covering OSINT, Active Directory, web application security, wireless security, exploitation fundamentals, note-taking, and penetration testing reporting.
CompTIA PenTest+ Reporting and Communication
Training focused on professional penetration testing reporting, handling sensitive information, communicating critical findings, and adapting technical reports to different audiences.
SOC Fundamentals — LetsDefend
Introduction to SOC operations, SIEM workflows, threat hunting, phishing analysis, and malware analysis.
Advanced Open Source Intelligence and Privacy — EC-Council
OSINT methodologies and tooling including Recon-ng, SpiderFoot, theHarvester, Shodan, Censys, Google Dorks, and related reconnaissance techniques.
Hacking WEP/WPA/WPA2 Wi-Fi Networks — EC-Council
Wireless security training covering WEP, WPA/WPA2, Aircrack-ng, Evil Twin attacks, WPS testing, and password attacks.
Ethical Hacking Essentials — EC-Council
Foundational training across ethical hacking, social engineering, wireless attacks, cloud security, malware, and defensive countermeasures.
Ingeniería Social para IT — LinkedIn Learning
Training covering social engineering techniques, persuasion, information gathering, and their use within cybersecurity and Red Team operations.
🔗 Find Me Online
Open-source tools, research, and security projects.
Professional profile and security work.
Vulnerability research and bug bounty profile.
Technical notes and offensive security resources.
Labs & Training Profiles
📧 Work With Me
I’m open to collaborating with engineering and security teams on mobile application security assessments, offensive security research, vulnerability research, and application security projects.
For consulting, research collaborations, or security-related inquiries:
contact@mfumis.com