Matteo Rosi is a Staff Security Engineer and OSCP-certified researcher with 11 years of experience combining software development, GNU/Linux system administration, and hands-on Blue Team leadership. He has led SOC operations, built security monitoring and incident response capabilities, and innovated new defensive services for companies from startups to enterprise (including roles at Telepass, Contrast Security, Arduino and Qualcomm). Matteo contributes to open-source security tooling—authoring a Maltiverse analyzer for Cortex and extending the boofuzz fuzzing framework—demonstrating a focus on pragmatic integrations and improved observability. With a PhD-level research background in network security and a history of mentoring security teams, he blends rigorous threat analysis with operational delivery. Based in Florence, Italy, he often bridges research and production by turning academic insights into deployable detection and mitigation controls.
11 years of coding experience
14 years of employment as a software developer
Research Doctorate (PhD) Computer Science Telecommunications Network Security, Research Doctorate (PhD) Computer Science Telecommunications Network Security at Università degli Studi di Firenze
Contributions:13 commits, 1 PR, 4 comments in 6 months
Contributions summary:Matteo's primary contributions involved developing and maintaining the Maltiverse analyzer within the Cortex platform. Their work included adding initial versions of the analyzer, fixing a type error, merging changes, and adding necessary templates for reporting. They focused on integrating the Maltiverse API to query data and report findings based on the data type, specifically focusing on file, URL, domain, IP, and hash analysis. The user also added support for reporting the results, including a summary and classification levels.
A fork and successor of the Sulley Fuzzing Framework
Role in this project:
Back-end Developer
Contributions:8 commits, 3 PRs, 4 comments in 14 days
Contributions summary:Matteo primarily focused on extending the functionality of the boofuzz framework. Their contributions included adding a new primitive, `s_from_file`, to read fuzz values from files, and refactoring the existing code to use the `BasePrimitive` class. Furthermore, the user implemented a CSV-formatted logger to track fuzzing output. These changes demonstrate a focus on improving the framework's flexibility and logging capabilities.
fuzzingpythonsecurity
Find and Hire Top DevelopersWe’ve analyzed the programming source code of over 60 million software developers on GitHub and scored them by 50,000 skills. Sign-up on Prog,AI to search for software developers.