Mattias Amo Fermin
White-hat pentesting, security research, reverse engineering, and software development — Gainesville, FL.
- whoami?
- good question. white-hat pentesting · security research · software development
- work
- web security, Windows/Linux, reverse engineering, automation, and lab infrastructure
- focus
- windows/linux · web security · reverse engineering · automation
- seeking
- security analyst · junior security engineer · swe roles
Windows Security Research
Windows privilege-boundary research covering UAC, COM, auto-elevation, and defensive visibility in controlled lab environments.
Windows Internals Tooling
Zig and Win32 experiments covering dynamic library loading, module resolution, GDI, and PE/loader behavior.
Detection Validation
Controlled testing of security telemetry and endpoint visibility using benign artifacts and repeatable lab scenarios.
Binary Analysis
IDA Pro workflows for static analysis, function triage, decompilation review, annotation, and AI-assisted analysis.
AI-Assisted Tooling
MCP-based tooling and agent workflows for software development and reverse-engineering tasks.
CTF & Practice Labs
Hands-on practice across web, binary, and forensics challenges, with emphasis on repeatable testing and technical writeups.
Selected projects and technical work — click a project for details. Source stays private (drwx------); each project is documented as a full technical writeup instead.
Research into Windows privilege boundaries on an instrumented host. Work covers UAC, COM interfaces, auto-elevation, and the practical boundaries enforced by the operating system.
Testing is paired with a defensive review of telemetry, endpoint visibility, and forensic artifacts.
A collection of focused Zig/Win32 experiments covering dynamic library loading, module resolution, GDI rendering, and PE/loader behavior.
The project provides low-level platform knowledge useful for both security research and defensive analysis.
A reverse-engineering workflow built around IDA Pro and MCP integration for assisted function triage, decompilation review, renaming, and annotation.
The goal is to reduce repetitive analysis work while keeping the investigation and final interpretation under human control.
Self-hosted services on an ARM single-board computer — Jellyfin, Immich, Navidrome, and the Linux administration that keeps them running.
Automation pipeline built on ComfyUI: model and LoRA management, prompt templating, and batch generation workflows packaged for reproducible deployment — environment setup, config, and launch scripts included.
About
White-hat pentesting, security research, reverse engineering, and software development. My current work spans Windows/Linux systems, web application security, binary analysis, automation, and lab infrastructure.
I spend a lot of time in controlled environments testing systems, building tooling, and documenting what I find.
Skills
- offensive
- White-hat web application testing, Windows/Linux security research, authorized penetration-testing labs, CTF practice
- defensive
- Detection validation, endpoint telemetry, controlled artifact testing, lab instrumentation
- reverse eng.
- IDA Pro static analysis, decompilation review, binary triage, MCP-based analysis tooling
- tools
- IDA Pro · Ghidra · Burp Suite · Nmap · Wireshark · Metasploit · Sysinternals · gobuster · Docker
- languages
- Python · Go · TypeScript/JavaScript · C# · Zig · PowerShell · Bash · SQL
- systems
- Windows internals, Linux administration (Debian daily-driver, Arch experience), self-hosted services (Jellyfin, Immich, Navidrome), Active Directory basics, network segmentation, Git
- ai dev
- MCP integrations, agent-assisted development, LLM tooling for software and analysis workflows
Get in touch
Security roles, SWE roles, collaboration, or questions about any of the work on this site.
- mattias.fermin@proton.me
- github
- github.com/mattiasamofermin
- linkedin.com/in/mattiasfermin
- resume
- resume.pdf
- location
- Gainesville, FL — open to remote / relocation