Skip to content
View lilloX's full-sized avatar

Highlights

  • Pro

Block or report lilloX

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
lillox/README.md

Hi, I'm Domenico "LilloX" Malorni

Principal Security Engineer · Penetration Tester · Red Teamer

Based in Barcelona 🇪🇸 · Working @ Cimpress España

About me

I break things for a living. Specializing in offensive security — web application penetration testing, red team operations, and increasingly, AI/LLM security research.

Member of the SWAT team (Security & Web Application Testing) at Cimpress, where I run internal security assessments and offensive engagements across the group's business units.

  • 🔴 Pentest & Red Team
  • 🤖 AI/LLM Security — MCP security testing, agentic attack surfaces
  • ☁️ AWS offensive security

Projects

Project Description
mcp-striker Deterministic exploit validation for MCP servers — enumerate attack surfaces, execute controlled security probes, generate re-playable evidence without an LLM in the loop
routerPWN Router credential recovery tool — ⭐ 36

Forks I actually use

  • evilgophish — evilginx2 + gophish combined
  • evilginx2 — MitM phishing framework for 2FA bypass
  • gophish — Open-source phishing toolkit
  • impacket — Python classes for network protocols

Skills & Tools

Area Stack
Offensive Pentest · Red Team · Phishing · Social Engineering
Cloud AWS Security Assessment · IAM · EC2/S3 abuse vectors
AI/LLM MCP Security Testing · Prompt Injection · Agentic attack surfaces
Languages Python · Go · Bash · PowerShell

🇮🇹 Italian · 🇬🇧 English · 🇪🇸 Español


Pinned Loading

  1. mcp-striker mcp-striker Public

    Deterministic exploit validation for MCP servers — enumerate attack surfaces, execute controlled security probes, and generate replayable evidence without an LLM in the loop.

    Python

  2. routerPWN routerPWN Public

    A tool for recover router password

    Python 36 13