About Me
I am a Cyber Threat Researcher with a background spanning identity threat research, phishing investigations, incident response, threat hunting and security operations. Since 2017, I have helped international organizations in a wide range of sectors investigate, contain and remediate threats across diverse environments.
I also build open security tools. I enjoy turning noisy data into practical intelligence with AI, cloud services and APIs.
Projects
An open feed of indicators shared by the security community
TweetFeed collects and organizes indicators of compromise posted on X. It focuses on URLs, domains, IP addresses and file hashes, and publishes them as an open feed.
Suspicious phishing sites, captured and enriched
phishunt identifies and monitors suspicious phishing sites. It captures them, enriches them with hosting, certificate and network context, and publishes the results as an open feed.
Experience
Part of Okta’s Identity Threat Research team, researching identity-focused threats and attacker tactics, techniques and procedures.
A few pieces of research published on the Okta Threat Intelligence blog:
- Aug. 23, 2026First on the scene of the (cyber)crime
- May 2, 2026Tycoon 2FA phishing actors disperse, branch into new attacks
- Dec. 19, 2025Jobseekers exploited in fake recruiter phishing campaigns
- Sep. 30, 2025EvilProxy phishing campaign leverages convincing impersonations of enterprise applications
- Aug. 28, 2025Attackers target hotelier accounts in malvertising and phishing campaign
- Jun. 19, 2025How this ClickFix campaign leads to Redline Stealer
Worked in Cloud Software Group’s global Security Operations Center, handling 24/7 incident response, threat hunting and detection tuning.
Key Responsibilities:
- Analyzed, contained and remediated malware, malicious email campaigns, fraud and abuse, insider threats and data-loss incidents
- Hunted threats and researched malware and phishing campaigns, translating findings into concrete mitigations
- Partnered with SIEM and Detection Engineering to tune alerts, reduce noise and improve detection performance
Worked in Banco Santander’s Global SOC, providing 24/7 monitoring and an on-call service to the bank’s entities worldwide.
Key Responsibilities:
- Performed in-depth investigation and mitigation of security incidents
- Monitored web traffic and critical SWIFT assets, investigating malware, phishing, DDoS and brute-force activity
- Supported fraud prevention across phishing, suspicious email, compromised cards, mule accounts, data leaks and impersonation
Worked in Deloitte’s CyberSOC, delivering managed security services for national and international clients.
Key Responsibilities:
- Conducted initial triage of SIEM alerts to identify potential threats
- Applied playbooks and immediate containment or remediation measures when required
- Escalated potential incidents with the context and evidence needed for further investigation
Education
Universidad de Sevilla
Master's Degree in Telecommunications Engineering
2015 - 2019
Advanced study of telecommunications networks and systems, including network architecture, signal processing, wireless communications and network security.
Universidad de Sevilla
Bachelor's Degree in Telecommunications Engineering
2011 - 2015
Foundations in telecommunications engineering, computer science and software development.
Certifications and Courses
- GIAC Security Essentials (GSEC) / SANS SEC401 [badge]
- MITRE ATT&CK Defender™ - Fundamentals Badge Training [badge]
- MITRE ATT&CK Defender™ - Cyber Threat Intelligence Certification Training [badge]
- MITRE ATT&CK Defender™ - SOC Assessments Certification Training [badge]
- Security Engineering on AWS
- Architecting on AWS - Accelerator
- ITIL Foundation [badge]
In the News
- Telenotícies migdia [TV3 - midday TV news (~32:15)]
- Telenotícies migdia [TV3 - midday TV news (~27:48)]
- Se ofrece ciberataque gratis en Telegram: el nuevo anzuelo de los robos ‘online’ [elconfidencial.com]
- Siguen las campañas de phishing suplantando a la Agencia Tributaria, ahora también por SMS [ESET blog]
- Están suplantando la web de Correos con kits vendidos en Telegram que usan sus bots para recopilar contraseñas. Y hay muchos kits así [genbeta.com]
- Así pueden estafarte con la declaración de la Renta [elcorreo.com]
- Telegram abre paso a la venta de kits para suplantar webs como la de Correos a través de bots [mundodeportivo.com]
- phishunt.io, cazando phishings [derechodelared.com]
- Suplantan la identidad de tenistas como Rafa Nadal para incentivar la descarga de vídeos con malware [20minutos.es]
- El ciberataque vía Youtube que ha suplantado a Nadal o a Djokovic durante Wimbledon [escudodigital.com]
- Continúan los SMS con falsos envíos de FedEx: cómo identificarlos y eliminar esta amenaza [ESET blog]
- FedexBanker: El nuevo troyano bancario para Android que utiliza tus paquetes para robarte las credenciales [hispasec.com]
- Los timos con criptomonedas que usan imágenes de famosos continúan muy activos [ESET blog]
- How does a modded crypto wallet steal credentials of an user? [@themalwarebug - medium.com]
- Aplicación maliciosa para Android se hace pasar por una versión de la cartera de criptomonedas MetaMask [ESET blog]
- Best Cyber Threat Intelligence Feeds [silentpush.com]
A Little More About Me
- Enneagram Type 5
- Member of Curated Intelligence Trust Group
- Enjoy lifting weights and riding my bike to avoid burnout