Offensive Security Professional & Red Teamer
Specializing in web, API, network, and Active Directory penetration testing. Passionate about securing critical systems and breaking things to make them stronger.
Core Expertise
Web & API Pentesting
Deep expertise in OWASP Top 10, advanced injection attacks, authentication flaws, business logic vulnerabilities, and modern API security.
Network & Infrastructure
Internal and external VAPT, firewall and DNS configuration reviews, endpoint security assessments, and real-world attack simulations.
Active Directory
Advanced AD enumeration, privilege escalation path analysis, lateral movement, credential abuse, and post-exploitation in enterprise environments.
Red Teaming
Adversary simulation, defense evasion, phishing simulation campaigns with GoPhish & PhishingBox, and full-chain attack development.
Vulnerability Assessment
Comprehensive internal and external vulnerability assessments across enterprise environments using Nessus, covering OS, service, and configuration weaknesses with CVSS risk rating.
Wireless Security
Wireless network penetration testing and Bluetooth security assessments using dedicated hardware adapters in authorized environments.
Mobile App Pentesting
Mobile application security assessments covering insecure data storage, improper authentication, and platform-specific vulnerabilities on Android and iOS.
Explore My Work
Dive into my detailed writeups on vulnerabilities I've discovered, check out my custom security tools, or read about the latest cybersecurity trends on my blog.
~ whoami
ruwantha_harshamal
~ cat skills.txt
['Web Pentesting', 'API Sec', 'Network', 'AD', 'Red Teaming']
_
Need a Penetration Test?
I offer professional security assessment services — from web application and API testing to full Active Directory red team engagements. Let's identify your attack surface before adversaries do.