About

Curiosity, offensive thinking, responsible reporting.

I’m Isira Adithya, a cyber security researcher and ethical hacker focused on web, API, and offensive security research.

Dossier Portrait of Isira Adithya

Isira Adithya

Security researcher

Focus
Offensive security
Specialty
Web · API · Cloud
Base
Sri Lanka

Threat surface

A repeatable research route.

Each investigation moves through the same loop: discover the surface, map the moving parts, test assumptions, validate impact, report clearly, then retest the fix.

  1. 01 Recon
  2. 02 Attack surface mapping
  3. 03 Testing
  4. 04 Exploitation and validation
  5. 05 Report
  6. 06 Retest
659 Intigriti submissions
418 Accepted reports
#12 Intigriti rank
41 HackerOne thanks
Exceptional Streak tier

Public stats cached · last sync Jul 6, 2026 01:12 UTC

Background

Understanding how systems fail, then helping teams fix them.

My work sits between curiosity and responsibility: finding where systems break, documenting root cause clearly, and helping teams reduce risk before issues become real-world incidents.

I spend most of my time researching modern web attack surfaces, reporting vulnerabilities through bug bounty programs, building small security workflows, and sharing what I learn through writeups.

2010

Starting school

I started my schooling at Lunugala Central College, where I studied from Grade 1 through Grade 10.

2018

First lines of code

At 14, I started teaching myself to code. It was the beginning of a lasting curiosity about how systems work.

2019

Changing schools

At 15, I moved to Bandarawela Central College, where I continued through my O/Ls.

2019

Turning to security

At 15, that curiosity turned toward security. I began playing CTFs, spent time on the TryHackMe leaderboards, and later moved on to Hack The Box.

Early 2021

Choosing bug bounty

After finishing my O/Ls at 16, I decided to try bug bounty hunting alongside my A/L studies.

Apr 2021

First bounty

I earned my first paid bounty, from Intigriti. It taught me that a clear, well-written report matters as much as the finding itself.

Aug 2021

Stepping away from A/Ls

I chose to step away from A/Ls. The long road to university did not feel like the right use of my time, so I focused on the work that was already working for me.

Late 2021

Moving to Colombo

With income from bug bounties, I enrolled at NSBM Green University and moved to Colombo on my own. The start was stressful and took some adjusting, but it was a fresh beginning.

2023

Finding stability

By this point things had settled. I was supporting myself comfortably and bought my first vehicle.

Aug 2025

First home

I bought my first house — a milestone I am quietly proud of.

Dec 2025

Graduating

I graduated with First Class Honours in Computer Security, a University of Plymouth degree through NSBM, finishing top of my batch. Along the way I played CTFs with my team, supported ISACA and Hackathon Hub, and helped run hackathons and other events.

Now

Web and API research

Today I research modern web and API attack surfaces through bug bounty programs, tooling, and ongoing learning.