> For the complete documentation index, see [llms.txt](https://hackermater.gitbook.io/pentesting-notes/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://hackermater.gitbook.io/pentesting-notes/readme.md).

# Index

Offensive AppSec notes and practical Cheat Sheets covering: Web, API, and Mobile security.

The goal of this GitBook is simple: keep useful commands, testing workflows, attack-surface notes, and research references in one place so they are easy to use during an assessment.

#### Main areas

* 🕸️ **Web Application Security** — reconnaissance, authentication, authorization, injection, client-side issues, business logic, and bug bounty workflows.
* 📲 **Mobile Pentesting** — shared mobile methodology plus dedicated Android and iOS cheat sheets.
* 🌐 **API Security** — REST, GraphQL, authentication, authorization, schema discovery, fuzzing, and business logic.
* 🛠️ **Offensive Security Tooling** — open-source tools and reproducible testing environments used in research and assessments.
* 🤺 **Red Teaming / Research Notes** — red team concepts, OSINT, social engineering, and supporting research notes.

#### About me

I'm **Mateo Fumis** — Security Researcher · Offensive Security Engineer.

My work focuses on Application Security, vulnerability research, reverse engineering, dynamic instrumentation, and offensive security tooling across **Web, API, and Mobile** environments.

#### Selected work

* [AndroidManifestExplorer](https://github.com/mateofumis/AndroidManifestExplorer) — Android attack-surface discovery from `AndroidManifest.xml`.
* [DumpDork](https://github.com/mateofumis/dumpdork) — search-driven OSINT and reconnaissance.
* [fridaDownloader](https://github.com/mateofumis/fridaDownloader) — Frida Server/Gadget setup helper.
* [Mobile Android Pentesting Setup](https://hub.docker.com/r/hackermater/mobile-pentesting-setup) — reproducible Android testing environment.

#### Research & writing

Research, tutorials, and vulnerability write-ups are published at [mfumis.com](https://www.mfumis.com/).

This GitBook intentionally stays closer to a **working cheat sheet** than a textbook. Canonical definitions and standards remain with projects such as OWASP, NIST, MITRE, and platform vendors.

#### Contact

* **Website:** [mfumis.com](https://www.mfumis.com/)
* **LinkedIn:** [Mateo Gabriel Fumis](https://www.linkedin.com/in/mateo-gabriel-fumis)
* **Email:** <contact@mfumis.com>
* **GitHub**: [github.com/mateofumis](https://github.com/mateofumis)
