Security Engineer — Sri Lanka

Nipun Dilshan
Senevirathne

Security Engineer / Bug Bounty Hunter / Offensive Tooling

I specialize in identifying high-impact, logic-based vulnerabilities that automated scanners consistently overlook — flaws that surface only when individually valid actions combine into an outcome the system was never designed to allow. Alongside manual assessment, I engineer the tooling that makes that process faster, more repeatable, and more precise.

Open to security engagements mail@nipundilshan.com
ASCII-rendered portrait of Nipun Dilshan Senevirathne
MOST WANTED — LOGIC FLAWS ACTIVE
What I Work On

Depth over checklists.

Automated scanners cover the obvious. My work starts where they stop — chaining small, legitimate-looking behaviors into something that shouldn't be possible.

Web Exploitation

Manual assessment of authentication, session handling, and application state — where real impact hides.

Logic-Based Flaws

Business-logic and access-control gaps — IDOR, privilege boundaries, workflow bypasses scanners can't reason about.

Recon Automation

Custom tooling for attack-surface discovery — dorking, fuzzing, and secret detection at a scale manual review can't match.

Secure Tooling

Building the extensions and scripts I wish existed — then publishing them for the community to harden further.

Selected Work

Tools I've built and shipped.

A mix of offensive security tooling and unrelated systems engineering — all public, all maintained on GitHub.

ultrafuzz — Claude Skill

AI Tooling

An ultra-grade AI-powered web fuzzing skill for Claude: bulk target ingestion, AI-generated wordlists, tech-stack profiling, vulnerability triage, and automated security reporting.

View repository

Simple-GitDorker

Shell

A lightweight, efficient GitHub dorking script that identifies sensitive exposures in authorized environments — automating discovery of high-risk keywords and misconfigurations.

View repository

Secret Scanner for Burp Suite

Python

A Burp Suite extension built for high-precision, real-time detection of leaked credentials and API keys during authorized security testing.

View repository

TraderAuto V2 — Compounding Suite

MQL5

A professional-grade automated trading engine executing an aggressive compounding strategy across major Forex pairs on 1-minute timeframes, with a Windows dashboard for live control.

View repository
Get in touch

Always open to a direct conversation.

Contact