Skip to content

Navigation Menu

Sign in
Appearance settings

Search code, repositories, users, issues, pull requests...

Provide feedback

We read every piece of feedback, and take your input very seriously.

Saved searches

Use saved searches to filter your results more quickly

Sign up
Appearance settings
@ameeshaheshan
ameeshaheshan
Follow
View ameeshaheshan's full-sized avatar
:octocat:
CodingπŸ’œ

Ameesha Heshan ameeshaheshan

:octocat:
CodingπŸ’œ
Information Security | Penetration Tester | Security Researcher | Threat Hunting Cybersecurity Analyst | API Security | Network Security πŸ–₯οΈπŸ–€

Block or report ameeshaheshan

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
ameeshaheshan /README.md

πŸ–₯️ SYSTEM INFORMATION

β”Œβ”€β”€(rootγ‰Ώnova-exzzr)-[~/profile]
└─$ cat identity.sh
#!/bin/bash
# ═══════════════════════════════════════════════════════════
# IDENTITY MATRIX
# ═══════════════════════════════════════════════════════════
export IDENTITY="Ameesha Heshan"
export CODENAME="NOVA EXZZR" 
export ROLE="Cybersecurity Specialist | Ethical Hacker | SOC Analyst"
export STATUS="Active - First Year @ CINEC CAMPUS, Sri Lanka"
export CLEARANCE="TOP_SECRET"
# ═══════════════════════════════════════════════════════════
# MISSION BRIEFING
# ═══════════════════════════════════════════════════════════
MISSION_OBJECTIVES=(
 "🎯 Web Application Penetration Testing"
 "πŸ› Bug Bounty Hunting (HackerOne | Bugcrowd)"
 "πŸ›‘οΈ Network Security & Infrastructure Hardening"
 "πŸ” Security Code Review & Vulnerability Assessment"
 "πŸ’‰ Exploit Development & Red Team Operations"
 "πŸ“Š Security Operations Center (SOC) Analysis"
)
# ═══════════════════════════════════════════════════════════
# CORE ATTRIBUTES
# ═══════════════════════════════════════════════════════════
LANGUAGES=("English" "Sinhala")
CONTACT="ameeshaheshan251@gmail.com"
PHILOSOPHY="Life is full of choices...choose wisely! 🎯"
# ═══════════════════════════════════════════════════════════
# ACTIVE LEARNING
# ═══════════════════════════════════════════════════════════
CURRENT_TRAINING=(
 "[β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–‘β–‘] 80% Advanced Penetration Testing"
 "[β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–‘β–‘β–‘] 70% Cloud Security (AWS/Azure/GCP)"
 "[β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–‘β–‘β–‘β–‘] 60% Malware Analysis & Reverse Engineering"
 "[β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–‘β–‘] 80% Machine Learning in Cybersecurity"
 "[β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–‘β–‘β–‘] 70% Threat Intelligence & OSINT"
)
echo "[+] System initialized successfully"
echo "[+] Ready for engagement..."

βš”οΈ OFFENSIVE SECURITY ARSENAL

πŸ”΄ EXPLOITATION FRAMEWORK

Kali Linux Parrot OS BlackArch

🎯 PENETRATION TESTING

Metasploit Burp Suite OWASP ZAP Cobalt Strike

πŸ” RECONNAISSANCE & OSINT

Nmap Wireshark Maltego Shodan SpiderFoot

πŸ’£ EXPLOITATION TOOLS

SQLMap Hydra John Hashcat BeEF

🌐 WEB APPLICATION TESTING

Nikto Gobuster Ffuf Wfuzz


πŸ›‘οΈ DEFENSIVE SECURITY OPERATIONS

πŸ”΅ SOC & SIEM PLATFORMS

Splunk ELK Stack QRadar ArcSight

🚨 INTRUSION DETECTION

Snort Suricata Zeek OSSEC

πŸ” ENDPOINT PROTECTION

CrowdStrike Carbon Black Cylance

πŸ“Š THREAT INTELLIGENCE

MISP OpenCTI ThreatConnect AlienVault


πŸ’» PROGRAMMING & SECURE DEVELOPMENT

🐍 SCRIPTING & AUTOMATION

Python Bash PowerShell Perl Ruby

βš™οΈ SYSTEMS PROGRAMMING

C C++ Rust Go

🌐 WEB SECURITY & DEVELOPMENT

JavaScript Node.js React Django Flask

πŸ”§ DEVSECOPS & INFRASTRUCTURE

Docker Kubernetes Jenkins Terraform Ansible

πŸ—„οΈ DATABASES & SECURITY

MySQL PostgreSQL MongoDB Redis SQLite

☁️ CLOUD SECURITY

AWS Azure GCP DigitalOcean

πŸ“± MOBILE SECURITY

Android iOS Frida


πŸ“Š SKILL PROFICIENCY MATRIX

β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”
β”‚ CYBERSECURITY CAPABILITIES β”‚
β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜
[OFFENSIVE OPERATIONS]
β”œβ”€ Web Application Penetration Testing β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–‘ 90%
β”œβ”€ Network Penetration Testing β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–‘β–‘ 85%
β”œβ”€ Bug Bounty Hunting β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–‘ 90%
β”œβ”€ Exploit Development β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–‘β–‘β–‘β–‘β–‘β–‘ 75%
β”œβ”€ Social Engineering β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–‘β–‘β–‘ 80%
└─ Red Team Operations β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–‘β–‘β–‘β–‘β–‘ 75%
[DEFENSIVE OPERATIONS]
β”œβ”€ SOC Analysis & Monitoring β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–‘β–‘β–‘β–‘β–‘ 80%
β”œβ”€ Incident Response β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–‘β–‘β–‘β–‘β–‘β–‘ 75%
β”œβ”€ Threat Hunting β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–‘β–‘β–‘β–‘β–‘β–‘β–‘ 70%
β”œβ”€ SIEM Configuration β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–‘β–‘β–‘β–‘β–‘β–‘ 75%
β”œβ”€ Security Hardening β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–‘ 85%
└─ Vulnerability Management β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–‘ 85%
[DEVELOPMENT & ENGINEERING]
β”œβ”€ Secure Code Review β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–‘β–‘β–‘β–‘β–‘ 80%
β”œβ”€ DevSecOps Implementation β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–‘β–‘β–‘β–‘β–‘β–‘ 75%
β”œβ”€ Python Scripting β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–‘ 90%
β”œβ”€ Web Development β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–‘β–‘β–‘β–‘β–‘ 80%
β”œβ”€ API Security β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–‘ 85%
└─ Infrastructure as Code β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–‘β–‘β–‘β–‘β–‘β–‘β–‘ 70%
[DATA & INTELLIGENCE]
β”œβ”€ Machine Learning β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–‘β–‘β–‘β–‘β–‘β–‘ 75%
β”œβ”€ Data Science β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–‘β–‘β–‘β–‘β–‘ 80%
β”œβ”€ OSINT & Reconnaissance β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–‘ 90%
β”œβ”€ Threat Intelligence β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–‘β–‘β–‘β–‘β–‘ 80%
└─ Digital Forensics β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–‘β–‘β–‘β–‘β–‘β–‘β–‘ 70%

🎯 SPECIALIZED OPERATIONS

🎯 WEB APPLICATION PENETRATION TESTING
SQL Injection β€’ XSS β€’ CSRF β€’ SSRF β€’ XXE β€’ Deserialization β€’ Authentication Bypass

πŸ› BUG BOUNTY HUNTING
HackerOne β€’ Bugcrowd β€’ Intigriti β€’ YesWeHack β€’ CISA CVE β€’ Public Disclosure

🌐 NETWORK SECURITY
Firewall Configuration β€’ IDS/IPS β€’ VPN β€’ Network Segmentation β€’ Traffic Analysis

πŸ’» SECURE CODE REVIEW
Static Analysis β€’ Dynamic Analysis β€’ OWASP Top 10 β€’ Secure SDLC β€’ Code Auditing

βš”οΈ RED TEAM OPERATIONS
C2 Frameworks β€’ Lateral Movement β€’ Persistence β€’ Privilege Escalation β€’ Evasion

πŸ” SOC ANALYSIS
Log Analysis β€’ SIEM Operations β€’ Threat Detection β€’ Incident Triage β€’ Forensics


πŸ“ˆ GITHUB INTELLIGENCE


πŸ† ACHIEVEMENT UNLOCKED

trophy

πŸŽ“ CERTIFICATIONS & TRAINING

β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”
β”‚ CURRENT & PLANNED β”‚
β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜
+ [IN PROGRESS] Certified Ethical Hacker (CEH)
+ [IN PROGRESS] Offensive Security Certified Professional (OSCP)
+ [PLANNED] CompTIA Security+
+ [PLANNED] Certified Information Systems Security Professional (CISSP)
+ [PLANNED] GIAC Penetration Tester (GPEN)
+ [TRAINING] TryHackMe - Top 5% Global Ranking
+ [TRAINING] HackTheBox - Hacker Rank
+ [ACTIVE] Bug Bounty Programs - Multiple Platforms

🎯 CURRENT OPERATIONS

╔══════════════════════════════════════════════════════════════════════╗
β•‘ MISSION OBJECTIVES β•‘
╠══════════════════════════════════════════════════════════════════════╣
β•‘ β•‘
β•‘ ⚑ OPERATION PENTESTING β•‘
β•‘ └─ Mastering Advanced Web & Network Penetration Testing β•‘
β•‘ β•‘
β•‘ πŸ” OPERATION BOUNTY β•‘
β•‘ └─ Active Bug Hunting on HackerOne, Bugcrowd, Intigriti β•‘
β•‘ β•‘
β•‘ ☁️ OPERATION CLOUD-SEC β•‘
β•‘ └─ AWS & Azure Security Architecture & Best Practices β•‘
β•‘ β•‘
β•‘ πŸ€– OPERATION ML-SEC β•‘
β•‘ └─ Machine Learning for Threat Detection & Analysis β•‘
β•‘ β•‘
β•‘ πŸŽ“ OPERATION CERT β•‘
β•‘ └─ Preparing for CEH & OSCP Certifications β•‘
β•‘ β•‘
β•‘ πŸ’» OPERATION OPENSOURCE β•‘
β•‘ └─ Contributing to Security Tools & Vulnerability Databases β•‘
β•‘ β•‘
β•‘ πŸ“Š OPERATION DATA-SEC β•‘
β•‘ └─ Data Science & Security Analytics Research β•‘
β•‘ β•‘
β•šβ•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•

πŸ’­ SECURITY WISDOM

Personal Motto:
"Life is full of choices...choose wisely! 🎯"


πŸ”— SECURE COMMUNICATIONS


🐍 ACTIVITY TRACE

Snake animation


⚠️ SECURITY NOTICE

╔═══════════════════════════════════════════════════════════════╗
β•‘ AUTHORIZED USE ONLY β•‘
╠═══════════════════════════════════════════════════════════════╣
β•‘ β•‘
β•‘ All penetration testing and security research activities β•‘
β•‘ are conducted with proper authorization and within legal β•‘
β•‘ boundaries. I follow responsible disclosure practices and β•‘
β•‘ adhere to ethical hacking guidelines. β•‘
β•‘ β•‘
β•‘ πŸ›‘οΈ Ethical Hacking β•‘
β•‘ βš–οΈ Legal Compliance β•‘
β•‘ 🀝 Responsible Disclosure β•‘
β•‘ πŸ“‹ Proper Authorization β•‘
β•‘ β•‘
β•šβ•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•

πŸ“œ HACKER'S CREED

"""
THE ETHICAL HACKER'S CODE
"""
class EthicalHacker:
 def __init__(self):
 self.principles = {
 "integrity": "Always act with honesty and transparency",
 "respect": "Respect privacy and data of others",
 "responsibility": "Use skills for defensive purposes",
 "legality": "Operate within legal boundaries",
 "disclosure": "Practice responsible vulnerability disclosure",
 "improvement": "Continuously learn and share knowledge"
 }
 
 def mission_statement(self):
 return """
 I pledge to use my cybersecurity knowledge and skills
 to protect systems, defend against threats, and make
 the digital world a safer place for everyone.

 I will never use my abilities to cause harm, steal data,
 or compromise systems without explicit authorization.

 I am a guardian of the digital realm. πŸ›‘οΈ
 """
# Instance of commitment
nova_exzzr = EthicalHacker()
print(nova_exzzr.mission_statement())

[ CONNECTION ESTABLISHED ]
[ SECURE CHANNEL ACTIVE ]
[ READY FOR ENGAGEMENT ]

β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”
β”‚ "The quieter you become, the more you are able to hear." β”‚
β”‚ - Kali Linux Motto β”‚
β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜

πŸ” Stay Secure. Stay Anonymous. Stay Ethical. πŸ”


Β© 2026 Nova Exzzr | All Rights Reserved | Ethical Hacking | Responsible Disclosure

Popular repositories Loading

  1. NebulaDork NebulaDork Public

    NebulaDork is an open-source, high-speed Python tool for Google dorking that filters SQL-vulnerable URLs and web apps. It supports domain and file type filters, multi-threading, and CAPTCHA solving...

    Python 4

  2. ameeshaheshan ameeshaheshan Public

    3

  3. Simple_port_scanner Simple_port_scanner Public

    A Simple port scanner with Treading

    Python 3

  4. YT-Downloader YT-Downloader Public

    Python 2

  5. PanelFox PanelFox Public

    PanelFox 🦊 – is a powerful admin panel finder written in Python, designed to help security researchers and penetration testers discover hidden admin portals. It features deep URL crawling, smart fi...

    Python 2

  6. StealthyPaws StealthyPaws Public

    StealthyPaws 🐾 is a lightweight, efficient keylogger tool designed for ethical use. It logs keystrokes in real-time and sends log files to Telegram, ensuring discreet operation. With a simple comma...

    Python 1

AltStyle γ«γ‚ˆγ£γ¦ε€‰ζ›γ•γ‚ŒγŸγƒšγƒΌγ‚Έ (->γ‚ͺγƒͺγ‚ΈγƒŠγƒ«) /