M
Manuja Medhankara
COLOMBO, SRI LANKA // UTC+05:30
AVAILABLE FOR SECURITY AUDITS
// CYBERSECURITY SPECIALIST & SYSTEMS BUILDER

MANUJA MEDHANKARA

Engineering resilient defensive architectures and conducting offensive vulnerability assessments. Specialized in penetration testing, Linux infrastructure hardening, and high-performance open-source security utilities.

DOMAINS: Penetration Testing / Linux Hardening / Security Tooling / Zero-Trust Baseline
01

// PROFILE & SPECIFICATIONS

Bridging offensive research with hardened systems engineering.

Specialized in rigorous web application security assessments, offensive vulnerability chaining, and low-level Linux infrastructure hardening. My methodology pairs industrial compliance baselines with real-world adversarial testing techniques.

Beyond auditing, I build high-speed desktop security utilities in Rust and Tauri, create automated compliance auditors against CIS Benchmarks, and contribute to privacy-first open-source security software.

System Specifications
ROLE Cybersecurity Specialist & Systems Engineer
PRIMARY OS Arch Linux / Custom Hardened Kernel
SECURITY OS Kali Linux / Qubes OS
TOOLCHAIN Burp Suite, Metasploit, Wireshark, Nmap
LANGUAGES Rust, Python, Bash, TypeScript
STANDARDS CIS Benchmarks & NIST 800-53
PLATFORMS Hack The Box & TryHackMe
02

// CAPABILITIES & AUDIT DOMAINS

[ SEC.01 ]

Penetration Testing

Offensive web application security assessments, vulnerability chaining, and comprehensive blackbox auditing.

Scope: OWASP Top 10 · REST/GraphQL APIs · Business Logic
[ SYS.02 ]

Linux Hardening

System administration, kernel sysctl tuning, strict user permission models, and automated compliance auditing.

Scope: CIS Benchmarks · AppArmor · iptables/nftables · systemd
[ DEV.03 ]

Security Tooling

Engineering high-speed custom vulnerability scanners, automation daemons, and defensive auditing utilities.

Scope: Rust · Tauri v2 · Python · Bash Scripting
[ NET.04 ]

Network Recon

Packet inspection, service fingerprinting, protocol analysis, and external attack surface discovery.

Scope: Nmap · Wireshark · Scapy · Zeek
[ CLD.05 ]

Cloud & Container Sec

Container isolation, minimal base images, CI/CD secret scanning pipelines, and cloud posture evaluation.

Scope: Docker · AWS IAM · Trivy · GitHub Actions
[ FOR.06 ]

Incident Forensics

Digital forensics, payload inspection, endpoint artifact parsing, log analysis, and threat hunting.

Scope: Ghidra · GDB · Volatility · YARA
03

// SELECTED PROJECTS & ROADMAP

01

VulnRadar Security Scanner

v0.7 RELEASED Source ↗

Desktop security workstation and non-intrusive vulnerability auditor. Evaluates web attack surfaces, cryptographic posture, HTTP security headers, and generates 1-click remediation blueprints.

Passive audits for SSL/TLS, DMARC/SPF, and HTTP header hygiene
Attack surface heuristics detecting debug endpoints and parameter reflection
High-speed async TCP port discovery with banner inspection
Subdomain reconnaissance via Certificate Transparency logs (crt.sh)
Rust Tauri v2 Svelte 5 SQLite WAL
02

Linux Hardening Suite

ACTIVE STAGING Source ↗

Automated compliance and hardening engine for Linux infrastructure aligned with CIS Benchmarks and NIST 800-53 baselines.

Automated compliance evaluation for SSH, kernel sysctl, and firewall posture
Non-destructive dry-run validation with automatic configuration rollbacks
Modular multi-distribution support (Arch, Debian, Ubuntu)
Bash Python CIS Benchmarks Kernel Security
03

Network Recon Pro

ROADMAP Source ↗

Asset discovery and protocol analysis framework featuring service fingerprinting, CVE correlation, and structured security reports.

Asynchronous service and banner detection across segmented subnets
CVE catalog correlation engine with exportable Markdown & HTML reports
Python Scapy Nmap Network Security
04

Contact

Let's build something secure together.

Open for security consultations, penetration testing, systems engineering, compliance audits, and collaborative open-source tooling.