Mattias Amo Fermin
// cybersecurity · software development · security research

Mattias Amo Fermin

White-hat pentesting, security research, reverse engineering, and software development — Gainesville, FL.

open to security / SWE opportunities
root@mfermin — bash
// focus
whoami?
good question. white-hat pentesting · security research · software development
work
web security, Windows/Linux, reverse engineering, automation, and lab infrastructure
focus
windows/linux · web security · reverse engineering · automation
seeking
security analyst · junior security engineer · swe roles
ls ./highlights
./windows-research

Windows Security Research

Windows privilege-boundary research covering UAC, COM, auto-elevation, and defensive visibility in controlled lab environments.

./windows-internals

Windows Internals Tooling

Zig and Win32 experiments covering dynamic library loading, module resolution, GDI, and PE/loader behavior.

./detection

Detection Validation

Controlled testing of security telemetry and endpoint visibility using benign artifacts and repeatable lab scenarios.

./reverse-engineering

Binary Analysis

IDA Pro workflows for static analysis, function triage, decompilation review, annotation, and AI-assisted analysis.

./ai-development

AI-Assisted Tooling

MCP-based tooling and agent workflows for software development and reverse-engineering tasks.

./ctf-practice

CTF & Practice Labs

Hands-on practice across web, binary, and forensics challenges, with emphasis on repeatable testing and technical writeups.

echo $STACK
pythongotypescriptc#zigpowershellbashida probinary analysisweb pentestingctfnmapburp suitewiresharkghidrametasploitdockersqlactive directoryai-assisted dev / mcpself-hostingdebianarchwindows internalsgitcomfyui
ls -la ~/projects

Selected projects and technical work — click a project for details. Source stays private (drwx------); each project is documented as a full technical writeup instead.

permmodifiednamestack
windows internalsuac / comsysinternalsdetection

Research into Windows privilege boundaries on an instrumented host. Work covers UAC, COM interfaces, auto-elevation, and the practical boundaries enforced by the operating system.

Testing is paired with a defensive review of telemetry, endpoint visibility, and forensic artifacts.

source: private  ·  read full writeup →
zigwin32 apigdiloadlibrary

A collection of focused Zig/Win32 experiments covering dynamic library loading, module resolution, GDI rendering, and PE/loader behavior.

The project provides low-level platform knowledge useful for both security research and defensive analysis.

source: private  ·  read full writeup →
ida promcpai agentspython

A reverse-engineering workflow built around IDA Pro and MCP integration for assisted function triage, decompilation review, renaming, and annotation.

The goal is to reduce repetitive analysis work while keeping the investigation and final interpretation under human control.

source: private  ·  read full writeup →
orange pi 4 prolinux / armself-hostingdocker

Self-hosted services on an ARM single-board computer — Jellyfin, Immich, Navidrome, and the Linux administration that keeps them running.

source: private  ·  read full writeup →
comfyuipythonautomationdeployment

Automation pipeline built on ComfyUI: model and LoRA management, prompt templating, and batch generation workflows packaged for reproducible deployment — environment setup, config, and launch scripts included.

source: private  ·  read full writeup →
cat ~/about.txt

About

White-hat pentesting, security research, reverse engineering, and software development. My current work spans Windows/Linux systems, web application security, binary analysis, automation, and lab infrastructure.

I spend a lot of time in controlled environments testing systems, building tooling, and documenting what I find.

Skills

offensive
White-hat web application testing, Windows/Linux security research, authorized penetration-testing labs, CTF practice
defensive
Detection validation, endpoint telemetry, controlled artifact testing, lab instrumentation
reverse eng.
IDA Pro static analysis, decompilation review, binary triage, MCP-based analysis tooling
tools
IDA Pro · Ghidra · Burp Suite · Nmap · Wireshark · Metasploit · Sysinternals · gobuster · Docker
languages
Python · Go · TypeScript/JavaScript · C# · Zig · PowerShell · Bash · SQL
systems
Windows internals, Linux administration (Debian daily-driver, Arch experience), self-hosted services (Jellyfin, Immich, Navidrome), Active Directory basics, network segmentation, Git
ai dev
MCP integrations, agent-assisted development, LLM tooling for software and analysis workflows
cat ~/contact.json

Get in touch

Security roles, SWE roles, collaboration, or questions about any of the work on this site.

email
mattias.fermin@proton.me
github
github.com/mattiasamofermin
linkedin
linkedin.com/in/mattiasfermin
resume
resume.pdf
location
Gainesville, FL — open to remote / relocation
currently available for opportunities