Security operations
SOC work, SIEM tuning, incident response and vulnerability management on real production estates.
Security operations and machine learning are usually treated as separate trades. I work where they meet.
SOC work, SIEM tuning, incident response and vulnerability management on real production estates.
Network defence and IDS/IDPS, from Suricata gateways to deep-learning detectors.
Adversarial machine learning, hardening detection models against attacks designed to fool them.
I ran production security operations on the Microsoft stack for one of Sri Lanka's largest insurers, and owned the ISO/IEC 27001:2022 programme end to end.
Sri Lanka's first ISP. I worked a 24/7 shift-based NOC defending the islandwide backbone and the secure VPN services that keep banks and industrial customers connected.
Technical research and documentation across assigned projects. From September 2022 I led the intern group and coordinated tasks across the team.
Research projects, security tooling and the archives I keep. Each one carries the reasoning, not just a screenshot.
An MSc dissertation on adversarial training for deep-learning intrusion detection on the Controller Area Network. The attack that breaks the model is also the material you train it on.
A local-LLM OSINT pipeline that turns scattered recon into one prioritised, provenance-tracked brief. One scan of a low-value domain returns around 960 findings. Collection succeeds; judgment does not.
A Raspberry Pi 5 sits inline with a home's traffic and unifies Nmap, UFW and Suricata behind a deliberately simple mobile app. Protection moves from the endpoint to the gateway.
A passive Certificate Transparency audit of my own domain surfaced 600+ historical records and a spam-issuance pattern predating my ownership. The work was separating the one actionable line from the noise.
A living archive of antiques, books and historical objects, each documented with provenance, condition and valuation notes. Schema-first, like everything else I keep.
A working culinary archive of Sri Lankan home cooking alongside dishes gathered from elsewhere. Effort, diet, heat, occasion, and the story behind each one.
Ten working instruments across security, machine learning and AI. Each runs entirely in your browser, and each shows the working underneath rather than a verdict you have to take on faith.
Draw a digit, add an imperceptible perturbation, and watch the classifier flip while the image looks unchanged.
Add a bias a model is never told about. Its answer moves; its chain of thought never admits why.
Which ports the internet is attacking right now, live from a worldwide honeypot network.
A phishing URL inspector, a password strength lab, an IOC extractor, a CAN frame decoder and more.
A book on the mathematics behind machine learning, rebuilt from first principles for anyone shut out by the notation. Part 1, linear algebra, is complete at 12 chapters.
Multi-strategy adversarial training for deep-learning intrusion detection on the CAN bus, evaluated on a strictly de-duplicated CICIoV2024. To be open-sourced and submitted to peer-reviewed venues.
Measuring faithfulness, prioritisation quality and provenance retention when a small local model synthesises structured, multi-tool OSINT. Existing work evaluates prose; Glean's input is normalised entity records.
Before a symbol appears, there is a picture. Before the picture, there is a problem you can actually feel.
A book on the mathematics behind machine learning, rebuilt from first principles for anyone shut out by the notation. Part 1, linear algebra, is complete at 12 chapters.
I work at the intersection of cyber security and machine learning. My MSc dissertation explores adversarial training for deep-learning intrusion detection on the Controller Area Network, the nervous system of every modern car, using the CICIoV2024 dataset and techniques from the Adversarial Robustness Toolbox.
Before Plymouth I built NetEAGLE, a Raspberry Pi network gateway combining a Flask API, mobile app, Nmap, UFW and Suricata into a single home-network defender. Earlier still, I served as a Cyber Security Engineer at Union Assurance PLC and an Associate Engineer at Lanka Communications.
When I am not reading papers I am cataloguing antiques in The Meridian, documenting Sri Lankan and global recipes in Rampe, and refining the database that powers this site.
Whether you need an engineer on your team, a collaborator on research, or a consultant on a hard security problem, my inbox is open.