Hi, I'm Domenico "LilloX" Malorni
Principal Security Engineer · Penetration Tester · Red Teamer
Based in Barcelona 🇪🇸 · Working @ Cimpress España
About me
I break things for a living. Specializing in offensive security — web application penetration testing, red team operations, and increasingly, AI/LLM security research.
Member of the SWAT team (Security & Web Application Testing) at Cimpress, where I run internal security assessments and offensive engagements across the group's business units.
- 🔴 Pentest & Red Team
- 🤖 AI/LLM Security — MCP security testing, agentic attack surfaces
- ☁️ AWS offensive security
Projects
| Project | Description |
|---|---|
| mcp-striker | Deterministic exploit validation for MCP servers — enumerate attack surfaces, execute controlled security probes, generate re-playable evidence without an LLM in the loop |
| routerPWN | Router credential recovery tool — ⭐ 36 |
Forks I actually use
- evilgophish — evilginx2 + gophish combined
- evilginx2 — MitM phishing framework for 2FA bypass
- gophish — Open-source phishing toolkit
- impacket — Python classes for network protocols
Skills & Tools
| Area | Stack |
|---|---|
| Offensive | Pentest · Red Team · Phishing · Social Engineering |
| Cloud | AWS Security Assessment · IAM · EC2/S3 abuse vectors |
| AI/LLM | MCP Security Testing · Prompt Injection · Agentic attack surfaces |
| Languages | Python · Go · Bash · PowerShell |
🇮🇹 Italian · 🇬🇧 English · 🇪🇸 Español


