Offensive Security Professional

Offensive Security Professional & Red Teamer

Specializing in web, API, network, and Active Directory penetration testing. Passionate about securing critical systems and breaking things to make them stronger.

Core Expertise

Web & API Pentesting

Deep expertise in OWASP Top 10, advanced injection attacks, authentication flaws, business logic vulnerabilities, and modern API security.

Network & Infrastructure

Internal and external VAPT, firewall and DNS configuration reviews, endpoint security assessments, and real-world attack simulations.

Active Directory

Advanced AD enumeration, privilege escalation path analysis, lateral movement, credential abuse, and post-exploitation in enterprise environments.

Red Teaming

Adversary simulation, defense evasion, phishing simulation campaigns with GoPhish & PhishingBox, and full-chain attack development.

Vulnerability Assessment

Comprehensive internal and external vulnerability assessments across enterprise environments using Nessus, covering OS, service, and configuration weaknesses with CVSS risk rating.

Wireless Security

Wireless network penetration testing and Bluetooth security assessments using dedicated hardware adapters in authorized environments.

Mobile App Pentesting

Mobile application security assessments covering insecure data storage, improper authentication, and platform-specific vulnerabilities on Android and iOS.

Explore My Work

Dive into my detailed writeups on vulnerabilities I've discovered, check out my custom security tools, or read about the latest cybersecurity trends on my blog.

~ whoami

ruwantha_harshamal

~ cat skills.txt

['Web Pentesting', 'API Sec', 'Network', 'AD', 'Red Teaming']

_

Available for Engagements

Need a Penetration Test?

I offer professional security assessment services — from web application and API testing to full Active Directory red team engagements. Let's identify your attack surface before adversaries do.

Web App PentestingAPI SecurityNetwork VAPTActive DirectoryWirelessMobile AppPhishing Simulation