Cybersecurity undergraduate
Penetration testing · SOC · Security analysis
JanithGodage
- Web & network exploitation
- Detection engineering
- Sri Lanka · GMT+5:30
Some of the tools I work in
Selected work
ASPE — Attack Surface Prioritization Engine
Ingests raw recon, scores every host on a weighted 'interestingness' formula, clusters them semantically, and uses an LLM to rank the top 50 targets with attack-chain reasoning.
Security Misconfiguration Finder
FastAPI web scanner that fingerprints common web misconfigurations and scores them into a consultant-grade report.
PortScan
Browser-based recon console — TCP port scanning plus subdomain and virtual-host discovery, running entirely on localhost.
From the lab
TCP SYN Flooding: Exhausting the Handshake
A SYN flood weaponises the half-open connection: send the first packet of the handshake, never the third, and let the target's backlog fill with connections that never complete. A lab walkthrough with Metasploit and hping3.
From Dummy to SYSTEM: UAC Bypass and Privilege Escalation
A Meterpreter foothold as a standard user is only the start. Walking a low-priv shell up to NT AUTHORITY\SYSTEM by bypassing UAC — and why the SAM stays locked until you do.
LLMNR/NBT-NS Spoofing: Free Hashes on the LAN
Two legacy name-resolution fallbacks, enabled by default in Windows, will broadcast a credential-bearing authentication to whoever answers first. A step-by-step lab walkthrough — and how to switch it off.
Beamforming Feedback (BFI): Reviewing the Attack Surface
Modern Wi-Fi hands attackers a high-resolution view of the channel for free. A look at what compressed beamforming feedback actually exposes — and where the real risk sits versus the hype.
Verified
Certified Cybersecurity Foundations
Hackviser
AWS Security Fundamentals
Amazon Web Services (AWS)
AWS Educate Introduction to Cloud 101
AWS Educate
Python Essentials 1
Cisco
Introduction to CIP
OPSWAT Academy
Public repositories are the rest of the evidence — every project above links to its source.
About me
I got into security by breaking something I shouldn't have. I stayed because writing the rule that catches your own exploit is the best feedback loop in this field.
Red, blue, or purple — I care more about the people and the work than the colour of the team.
- Based
- Sri Lanka · GMT+5:30
- Focus
- Pentesting · SOC · Analysis
- Studying
- SLIIT · 3rd year
- Weekends
- CTFs and HackTheBox
Break it,
then catch it.
Recon & exploit
Web exploitation, network attack paths, and tooling that automates the boring parts of both. Burp, sqlmap, ffuf, Nmap, Metasploit.
Detection
Sigma rules, Suricata signatures, and Wazuh pipelines — written against attacks I ran myself, so I know exactly what they have to catch.
The loop
Writing a rule that catches your own exploit is a uniquely satisfying loop. Each side sharpens the other, which is why I want to work purple.
Written down
Every lab and finding gets a walkthrough — 5 of them so far, plus reference sheets, written for the next person who has to read them.
Let’s talk
Open to penetration testing, security analysis, and SOC work.
Engagements, research collaboration, or a CTF team — drop a line. I read everything and reply within 48 hours. PGP on request.
Or write direct to janithzgodage@gmail.com