Mobile security audits delivered across regulated and high risk industries.
Dimitris Pallis
London, UK.
Hi! I work in offensive security and have spent more than eight years testing systems and studying malicious Android apps. My work covers Android malware, reverse engineering and offensive security. I break apps down, recover protected code and payloads and document what they actually do. I also carry out penetration tests and red team work across mobile, web, APIs and cloud environments.
My work has covered advertising, retail, financial services, blockchain, publishing, nonprofits, gaming, payments and banking. Outside client work I speak at conferences and publish research and tools. I also help run a security community with thousands of members.
For security assessments, malware research, invited talks and general inquiries: dmitris@protonmail.com.
Key achievements
Reduction in bug bounty response time while managing a vulnerability disclosure program.
Time to promotion to senior penetration tester after joining a consulting practice.
Security research presented at major conferences in Dubai and Sofia.
- Collaborated directly with a leading mobile ecosystem team on app security and malware prevention for a global app marketplace.
- Recognised in a major security vendor’s Hall of Fame for vulnerability research.
- Built automation for decryption, code recovery, protection analysis and malware triage.
- Sponsored to attend and cover five international security, web3 and technology events.
- Completed the full OSCE³ certification path alongside red team and cloud security credentials.
Projects & research
I publish tools and practical research for malware analysis and offensive security.
NoDex: Android Malware Destroyer
Full Android malware investigations with threat reports, indicators, YARA rules and tools written for each sample. The first public report follows a commercial surveillance implant from entry point to final evidence.
BChecks
Reusable web and API checks for findings that turn up often.
Offensive and analysis scripts
Small tools that make security testing and malware analysis faster and more repeatable.
Hardened privacy fork
A version of a popular blocking tool with its tracking removed.
Research tools
String decryptors, payload extractors, native dumpers, protocol decoders and custom tracers built for samples that defeat standard tools.
Conference speaker
GISEC Global in Dubai · ETHSofia in Sofia
I have presented offensive security and vulnerability research to international audiences. I am also available for invited talks and interviews about Android malware, reverse engineering, mobile security and new attack techniques.
- Wrote Introduction to Internal Penetration Tests for a penetration testing magazine in December 2022.
- Published technical research on a private mobile API session header.
- Appeared on an industry certification body’s video channel and a red team interview series.
Expertise
Android malware research
I reverse engineer malicious apps to uncover their real behaviour. This includes removing obfuscation, recovering encrypted code and payloads, tracing native components and writing clear evidence based reports.
Mobile application security
I test mobile apps and the APIs behind them. My work covers authentication, payments, local storage, deep links, WebViews, platform misuse and the ways apps try to block analysis.
Penetration testing and red teaming
I have delivered more than 50 mobile audits as well as web, API, infrastructure and cloud assessments. I have also run phishing exercises, helped improve testing methods and mentored junior testers.
Security engineering and automation
I write scripts and internal tools to speed up repetitive analysis. I have built workflows for malware triage, code review, decryption and reporting and I am comfortable working with APIs, containers and delivery pipelines.
Credentials & education
Professional certifications
- OSCE³
- OSCP
- OSEP
- OSED
- OSWE
- CRTO
- AWS Cloud Security Specialty
- Microsoft AZ 500
Academic education
BSc studies in Electrical and Electronics Engineering, University of West Attica, Greece · 2013.
British and EU citizenship.
Community
I own a professional group for hackers with thousands of members and help run a live red team community. I help people get into cybersecurity through practical advice, résumé reviews, current tools and mentoring.
“A hard worker who is quick to learn, passionate about cybersecurity, approachable and a pleasure to work with.”
Former senior colleague
“Prepared, always improving, trustworthy and humble.”
Former manager