vidura@kandy:~$
Vidura Ranathunga
$whoami

Vidura Ranathunga

$

Self-motivated cybersecurity researcher and threat intelligence analyst with a track record in penetration testing, vulnerability disclosure, and SOC operations. Comfortable under pressure, sharp under deadline.

// STATUS
Threat Intel Analyst
Virtusa — since Apr 2026
4Proof Of Concepts
(2023–2024)
2022Active in security
& ICT since
15+Tools across offense,
defense & recon
profile

Built for the pressure of tight deadlines

Self-motivated and versatile individual with a successful record in ICT, network security, and software engineering. Practical experience spans system operations, cybersecurity, and project management — with a habit of hitting high standards even against tight schedules.

A cooperative teammate who's always acquiring new skill sets, now working as a Threat Intel Analyst at Virtusa after building SOC capability from the ground up at LiveWireCloud.

// LANGUAGES & TRAITS
Sinhala
English
Teamwork
Leadership
Critical thinking
technical skills

Stack & toolbelt

Languages, security discipline, and the tools used to get there.

languages
  • Python
  • Java
  • HTML / CSS
  • Bash
cybersecurity
  • Exploit development
  • Penetration testing
  • Vulnerability analysis
  • Buffer overflow (TOTOLINK routers)
  • Wi-Fi security
rf & iot
  • RFID-based access control
  • ESP32 development
  • MFRC522 RFID module
tools & platforms
  • Kali Linux
  • Metasploit / Burp Suite
  • Shodan API / Nuclei / Nmap
  • Nessus
  • ngrok
  • Arduino IDE
  • VMware / VirtualBox
soc operations
  • Wazuh
  • TheHive
  • EDR solutions
  • Vulnerability management
working style
  • Time management
  • Effective communication
  • Leadership
  • Critical thinking
projects & disclosures

Selected work

Vulnerability disclosures
Proof of concept

Independently identified and disclosed the following CVEs, plus reported an improper encryption issue found in the Telegram app.

CVE-2024-46377Proof of concept
CVE-2024-46451Proof of concept
CVE-2024-46986Proof of concept
CVE-2023-46747Proof of concept
Shodan-Quest Tool
Tool

A tool built to query the Shodan database for vulnerability analysis, using an educational API key to surface exposed and misconfigured targets.

RFID Access Control System
RF / IoT

Designed and implemented an RFID-based access control system on ESP32 with an MFRC522 reader, paired with a web portal for logging and monitoring entries.

experience

Recent history

APR 2026 — PRESENT Threat Intel Analyst Virtusa
  • Tracking emerging threats, TTPs, and indicators of compromise relevant to client environments
  • Turning raw intelligence into actionable reporting for security operations
2024 — APR 2026 Cloud Security Engineer LiveWireCloud (part-time)
  • Built a fully operational SOC using Wazuh, TheHive, and other EDR solutions
  • Worked across vulnerability management, from identification through remediation tracking
2022 — 2024 Freelance ICT Independent
  • Designed and implemented an RFID-based access control system with a web portal for logging and monitoring
  • Ran cybersecurity projects covering exploit writing and threat scanning with Shodan and Nuclei
  • Found and reported improper encryption in the Telegram app
  • Performed vulnerability analysis on heycarbon.com and livewirecloud.com
  • Contributed 3 scripts to the Nuclei open-source project
  • Updated the MFRC522 library
education

Academic background

BSc (Hons) in Information Technology, specialising in Cyber Security
Undergraduate · Class of 2024 (in progress)
Semester 1 — finished
  • Introduction to Programming
  • Data Communication Networks
  • Mathematics for Computing
  • Fundamentals of Computing
Semester 2 — finished
  • Discrete Mathematics
  • Data Structures and Algorithms
  • Object Oriented Programming
  • Technical Writing
contact

Let's talk security

Open to freelance engagements and collaboration on vulnerability research.

VR
Currently available for freelance work
Reach out for security research, disclosures, or SOC/cloud security collaboration.