Skip to content
View sandakelum97's full-sized avatar
🫡
🫡

Block or report sandakelum97

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
sandakelum97/README.md

THARAKA DISSANAYAKA

Senior Security & Systems Engineer

focus areas

$ whoami --verbose

  operator   : Tharaka Dissanayaka
  role       : Security Engineer · Services Security Team
  environment: MSSP · ~50 managed enterprise tenants
  base       : Colombo, Sri Lanka
  experience : 8+ years  ·  security, infrastructure, network
  focus      : [ SOC Ops, Threat Hunting, Vuln Mgmt, Firewall Eng ]
  reading    : Executive MSc, Information Security
  status     : ACTIVE ✓

GitHub Stats

stats

streak

top languages

trophies

profile views

### 8+ ### ~50 ### 17 ### MSc
YEARS IN SECURITY MANAGED TENANTS CERTIFICATIONS IN PROGRESS

01 · About

Security engineer with 8+ years across cybersecurity, enterprise infrastructure and network security. I run threat detection and endpoint defence for roughly 50 managed enterprise tenants at an Australian MSSP — detection triage, incident response, vulnerability management, and the occasional 2 a.m. containment call.

My background runs both ways. I came up through infrastructure — Windows Server, Active Directory, VMware, ERP, backup and DR — before moving into security. That shows up in how I triage: knowing why a line-of-business application spawns a strange-looking process is often the difference between a five-minute false positive and a three-hour incident.

Working belief — a detection you can't explain in a ticket note isn't a detection, it's a guess.


02 · Operating Areas


THREAT DETECTION

EDR/XDR triage · process lineage
LOLBin analysis · exclusion scoping
KQL threat hunting



INCIDENT RESPONSE

AiTM & token theft · BEC
account compromise · containment
post-incident review



VULNERABILITY MGMT

exposure analysis · CVE advisories
remediation prioritisation
closure criteria



IDENTITY & ACCESS

Entra ID · Conditional Access
MFA & passwordless
Zero Trust architecture



SOC OPERATIONS

SIEM detection engineering
alert triage at MSSP scale
playbooks & runbooks



EMAIL SECURITY

header authentication analysis
quarantine adjudication
tenant-wide purge & hunt



NETWORK SECURITY

FortiGate & SonicWall policy
IPsec / SSL VPN · VLANs
segmentation



GOVERNANCE

ISO 27001 · NIST CSF · COBIT
change management
client advisories



03 · Research

Executive MSc in Information Security · Asia e University, Malaysia · Nov 2025 – Dec 2026

Automating Environmental Decision Points in Stakeholder-Specific Vulnerability Categorization

A Multi-Tenant Evaluation Against CVSS-Based Remediation Baselines

THE GAP

Vulnerability prioritisation still runs on CVSS base scores, which describe a flaw in the abstract and say nothing about whether the affected system is internet-facing, patched, or business-critical. SSVC addresses that, but its environmental decision points are assigned by hand and don't scale.

THE QUESTION

Whether environmental factors — system exposure, mission impact — can be derived from managed service provider telemetry instead: asset inventories, internet exposure, patch state, business criticality. Completing the SSVC decision tree without manual analyst input.

WHY IT'S OPEN

Existing automation such as CISA Vulnrichment resolves the vulnerability-specific factors and stops there — the organisation-specific ones cannot be derived from public data. That half of the tree has no automated answer yet.

▸ Method and evaluation

Historical backtesting against public datasets — NVD, EPSS, CISA KEV, Vulnrichment — comparing automated SSVC prioritisation against conventional CVSS severity-based remediation.

Measure What it captures
Exploitation coverage Share of actually-exploited CVEs caught by each prioritisation scheme
Efficiency Precision of the remediation queue — how much effort goes to vulnerabilities that mattered
Remediation effort Total volume of work each approach demands

The environmental model is built either from aggregated, anonymised statistics drawn from a real multi-tenant managed services environment (subject to approval) or from a fully synthetic dataset where approval is unavailable.

What it settles: whether automated, context-aware prioritisation produces better remediation outcomes than severity-ranked patching — or whether the added machinery buys nothing a CVSS cutoff doesn't already deliver.


04 · Stack

▸ SOC & Threat Detection

Defender XDR CrowdStrike Sentinel Proofpoint ThreatLocker DarkWeb ID

▸ Incident Response & Threat Hunting

MITRE KQL

AiTM phishing investigation and token-theft response · EDR triage across process injection, AMSI tampering, VSS deletion and LSASS access · adversary emulation · CVE triage and threat intelligence correlation

▸ Vulnerability Management

Nessus Defender TVM Defender for Cloud SSVC

Remediation tracking, closure criteria, and client-facing exposure reporting.

▸ Identity & Access Management

Entra ID Conditional Access AD Azure GCP

MFA and passwordless rollout · RBAC and least-privilege design.

▸ Network & Firewall

FortiGate FortiManager SonicWall Cisco Auvik Inforcer Wireshark PRTG

IPsec and SSL VPN · VLAN design and segmentation · routing and switching.

▸ Tooling & Automation

ConnectWise PowerShell Python Node.js AppSheet Terraform Ansible Git

▸ Governance & Compliance

ISO 27001 NIST CSF COBIT Zero Trust

Change management · security runbook authoring · policy and control documentation.

▸ Infrastructure

Windows Server VMware Linux Dynamics M365


05 · Certifications


SC-100
Cybersecurity Architect Expert


SC-200
Security Operations Analyst


SC-300
Identity & Access Administrator


AZ-900
Azure Fundamentals


MS APPLIED SKILLS
Defend Against Cyberthreats
Defender XDR



ISC2 CC
Certified in Cybersecurity


CISCO CCNA
Enterprise & Security


CISCO CYBEROPS
CyberOps Associate


CISCO DEVNET
DevNet Associate


FORTINET NSE 3
Network Security Associate


SECOPS CNSP
Certified Network
Security Practitioner



MITRE ATT&CK
Defender Fundamentals


SENTINELONE
Singularity Admin Essentials


GOOGLE CYBERSECURITY
Professional Certificate


GOOGLE WORKSPACE
Professional Administrator


GOOGLE GENAI
Generative AI Leader


KODEKLOUD
DevOps Engineer Level 1

Credentials verifiable via the portfolio site

◈ In progress — TCM PNPT (Practical Network Penetration Tester) · Google Associate Cloud Engineer ○ Planned — ISC2 CISSP (Q3 2026) · HTB Certified Active Directory Bootcamp Expert

Education

Qualification Institution Period
Executive MSc in Information Security Asia e University (AeU), Malaysia Nov 2025 – Dec 2026
Diploma in Network Engineering National Institute of Business Management (NIBM) 2019 – 2021
Certificate in Linux Network Administration Turnkey IT Campus —

06 · Selected Work

mssp-soc-playbooks

KQL queries and detection playbooks from MSSP SOC operations.

SC200-SC300-study-plan

Structured study plan and notes for the Microsoft SC-200 and SC-300 exams.

security-training

Gamified security awareness platform — phishing and password challenges, leaderboards, JWT auth, PostgreSQL. · live

prompt-engineering-trainer

Hands-on tool for practising prompt patterns in security and productivity workflows.

sandakelum97.github.io

Portfolio site — Three.js background, live GitHub and Medium feeds, dark/light themes.

claude-skills · private

Version-controlled Agent Skills for SOC triage, CVE advisories and exposure analysis.


07 · Writing

I write up the things that took me too long to work out the first time — detection triage reasoning, vulnerability management practice, and the operational side of security that rarely makes it into vendor documentation.


08 · Activity





Colombo, Sri Lanka · All systems secure

Pinned Loading

  1. mssp-soc-playbooks mssp-soc-playbooks Public

    KQL queries and detection playbooks from real-world MSSP SOC operations

    1

  2. SC200-SC300-study-plan SC200-SC300-study-plan Public

    1

  3. security-training security-training Public

    JavaScript

  4. sandakelum97.github.io sandakelum97.github.io Public

    HTML 1