Offensive Security Specialist

Supun Hewagamage

Building Secure Futures

Offensive Security & Development

Passionate about building security tools and breaking systems to make them stronger

Security Specialist

Focused on offensive security, red teaming, and penetration testing. Active CTF player on TryHackMe, HackTheBox, picoCTF, CyberDefenders, and Hackviser. Specializing in web exploitation, malware analysis, reverse engineering, and network attacks.

Tool Developer

Building advanced security tools including forensic platforms, covert channel frameworks, reverse shell generators, and enumeration utilities. Proficient in Python, Bash, Java, JavaScript, C#, and full-stack development with modern web technologies.

Education & Certifications

HND Student at National Institute of Business Management (NIBM). Diploma Graduate with 3.83/4.0 GPA. Completed RH124 and RH134 of RHCSA at Red Hat Academy. DataCamp Associate Data Engineer certified. Preparing for professional certifications including OSCP, CEH, and eJPT.

Current Focus

Improving Python development skills and exploring containerization with Docker and Kubernetes. Expanding my security tool arsenal with advanced forensic capabilities. Active in CTF competitions and hackathons, constantly sharpening offensive security skills through practical challenges.

20+
Security Tools
78K+
Lines of Code
366
Binaries Cataloged
1400+
Techniques

Security Tools & Projects

Advanced offensive security tools built for penetration testing and security research

🔍

Filo

🛡️

Forensic Intelligence & Learning Operator - Battle-tested file forensics platform for security professionals. Transforms unknown binary blobs into classified, repairable artifacts with offline ML learning capabilities.

Python Production ML-Powered
Digital Forensics ML File Analysis
🌊

CoCo

🔐

Multi-protocol covert channel framework supporting ICMP, DNS, and HTTP with 7 evasion modes. Features ChaCha20 encryption for secure data exfiltration and communication.

Python Encrypted Multi-Protocol
Covert Channels Data Exfiltration Evasion
🐚

ShellHooks

💻

Comprehensive reverse shell generator supporting 20+ languages with 66+ variants. Available as both CLI and web interface for quick payload generation during assessments.

Multi-Language CLI + Web 66+ Variants
Reverse Shells Payload Generation Pentesting

GTFOBins-CLI

🔓

Linux privilege escalation reference tool cataloging 366 binaries with 1400+ exploitation techniques. Essential CLI utility for penetration testers and security researchers.

Python 366 Binaries 1400+ Techniques
Privilege Escalation Linux Security Reference Tool
View All Projects

Skills & Technologies

Languages

Python JavaScript Bash Java C# SQL

Offensive Tools

Burp Suite Metasploit nmap sqlmap Gobuster OWASP ZAP

Reverse Engineering

Ghidra Radare2 Cutter Wireshark

Development

Node.js React Next.js MongoDB PostgreSQL Docker