Skip to content

Cybersecurity undergraduate

Penetration testing · SOC · Security analysis

JanithGodage

  • Web & network exploitation
  • Detection engineering
  • Sri Lanka · GMT+5:30

Some of the tools I work in

Burp SuiteWiresharkMetasploitKaliLinuxDockertmuxOWASP Top 10SnortElasticKibanaLogstash

Selected work

From the lab

035 earned · 4 verifiable

Verified

04Background

About me

I got into security by breaking something I shouldn't have. I stayed because writing the rule that catches your own exploit is the best feedback loop in this field.

Red, blue, or purple — I care more about the people and the work than the colour of the team.

Based
Sri Lanka · GMT+5:30
Focus
Pentesting · SOC · Analysis
Studying
SLIIT · 3rd year
Weekends
CTFs and HackTheBox
Study
SLIIT
BSc (Hons) Information Technology — Cybersecurity
[3rd year]
Focus
Offensive
Web exploitation, network attack paths, and the tooling that automates the boring half of both
[red]
Detection
Sigma rules, Suricata signatures, and Wazuh pipelines — written against attacks I ran myself
[blue]
Tooling
Python and TypeScript utilities that take the repetitive part of an engagement off the table
[build]
Labs
PortSwigger Academy, HackTheBox, and CTF play — the reps behind everything above
[ongoing]
Research
Wi-Fi beamforming feedback and the embedded side. Early days; the writeups are where it shows
[open]
In-depth look
Download CVpdf · 27 KB

Break it,
then catch it.

Core foundations
01

Recon & exploit

Web exploitation, network attack paths, and tooling that automates the boring parts of both. Burp, sqlmap, ffuf, Nmap, Metasploit.

02

Detection

Sigma rules, Suricata signatures, and Wazuh pipelines — written against attacks I ran myself, so I know exactly what they have to catch.

03

The loop

Writing a rule that catches your own exploit is a uniquely satisfying loop. Each side sharpens the other, which is why I want to work purple.

04

Written down

Every lab and finding gets a walkthrough — 5 of them so far, plus reference sheets, written for the next person who has to read them.

Core competencies
Web ExploitationBurp Suite · sqlmap · ffuf · OWASP Top 10 · JWT abuse
Network & ReconNmap · Wireshark · Metasploit · Responder · Bloodhound
Detection / Blue TeamWazuh · Suricata · Sigma · ELK · MITRE ATT&CK
Crypto & ReversingGhidra · radare2 · pwntools · GDB · Frida
EnvironmentsKali · Docker · Linux · VSCode · tmux
05Reply within 48h

Let’s talk

EmailLinkedInGitHub

Open to penetration testing, security analysis, and SOC work.

Engagements, research collaboration, or a CTF team — drop a line. I read everything and reply within 48 hours. PGP on request.

Send a message

Or write direct to janithzgodage@gmail.com

Scrl0.00Crsr0.0
00 — INDEX