Portrait of Mateusz Adamczyk
about

Mateusz Adamczyk

aka m4t · m4teusz · offensive security researcher

I research offensive security and build the engineering scaffolding around it. My day-to-day moves between vulnerability discovery, exploit development, and the kind of platform work that lets a small team punch above its weight.

Over the last few years I've shipped CVE-class findings in identity providers, spoken at conferences in Europe and the US, and written a field manual on modern web exploitation. I split my time between long-form research, selective consulting, and mentoring engineers stepping into offensive work.

I write here to clarify my own thinking and to leave a trail for engineers solving the same problems. The bar I hold for posts is simple: they should be useful five years from now.

at a glance

Based
Warsaw, PL
Languages
Polish · English
Open to
Disclosure · consulting · speaking
Responds
Within 48h

focus

Web & API
Auth flows, request smuggling, server-side logic flaws.
Binary & RE
Userland exploitation, kernel 1-days, custom VMs.
Cloud & K8s
IAM design, container escapes, supply-chain reviews.
Red team
Tradecraft, AD attack paths, OPSEC-aware tooling.

stack

Burp SuiteGhidraIDA Proradare2fridaPythonRustGoCTypeScriptBloodHoundCertipyImpacketSliverMythic

selected timeline

  • 2025WOOT '25 paper · PKCE downgrade in public clients
  • 2025Speaker · CONFidence — "When the Identity Provider Lies"
  • 2024Released "Field Manual: Modern Web Exploitation"
  • 2024Workshop lead · x33fcon — AD CS red teaming
  • 2023Joined a red team practice — full-time engagements
  • 2021First CVE-class disclosure · web identity layer

elsewhere

contact

m4teusz.adamczyk@gmail.com

For research collaboration, responsible disclosure, or selective consulting. PGP key available on request.