Skip to content
View jankesec's full-sized avatar

Sponsoring

@curl

Highlights

  • Pro

Block or report jankesec

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
jankesec/README.md

Sevban Dönmez

Senior Cyber Security Consultant at PwC with 5+ years of corporate experience specializing in offensive security, vulnerability research, and penetration testing. Backed by 14+ years of hands-on security research, I have conducted more than 400 enterprise-grade penetration tests and discovered over 100 zero-day vulnerabilities across critical infrastructure and enterprise environments.

Official OWASP Author (WSTG) · Contributor to Mobile (MASTG) & AI (AITG) Standards.

Research & CVEs · Field Notes · Projects · PGP Key


Focus Areas

  • Vulnerability Research: Broad-spectrum vulnerability discovery, reverse engineering, and responsible disclosure across diverse software architectures, protocols, and enterprise bug bounty programs.
  • Offensive Security: Comprehensive adversary simulation, end-to-end red team operations, and offensive capability development across modern enterprise defense perimeters.
  • Penetration Testing: Full-scope penetration testing spanning web & mobile applications, internal/external networks, cloud environments, APIs, and enterprise identity infrastructures.

Selected Security Tooling

Project Focus Stack
mcpbait Red teaming framework for AI agents and Model Context Protocol (MCP) integrations. Python
driftnet2 High-performance packet capture and credential extractor leveraging eBPF/XDP. Go, eBPF
macharden Modern macOS hardening, baseline drift & audit engine (50 CIS/NIST controls, SARIF). Zsh, Bash
evilcorp-ios Intentionally vulnerable iOS benchmark application mapped to OWASP MASVS v2 & MASWE. Swift
ghostlink Multi-channel Out-of-Band (OOB) covert C2 and data exfiltration framework. Go

Ecosystem Contributions & Disclosures

  • OWASP Foundation: Official Author of the Web Security Testing Guide (WSTG), with active contributions across the AI Testing Guide (AITG) and Mobile Application Security Testing Guide (MASTG).
  • Open Source Ecosystem & Tooling: Active voluntary contributor dedicated to supporting and securing the open-source community, with upstream contributions across ProjectDiscovery, security frameworks, and Linux utilities.
  • Vulnerability Research & Bug Bounty: Author of credited CVEs across enterprise software and network appliances (tracked via TR-CERT & NVD), with a proven responsible disclosure track record across enterprise bug bounty programs. Disclosures and write-ups published at jankesec.com/cves.

Cryptographic Identity & Contact

Coordinated disclosures and signed communications:

Identity        : Sevban Dönmez (jankesec)
PGP Fingerprint : FF0A 7D83 6751 CCE3 F9CC F574 FCF8 39FB 7F00 4626
Key ID          : 5FDB257F4AAE8C3F
Public Key      : https://jankesec.com/pgp-key.txt
Verification    : https://jankesec.com/pgp/
Signed Comms    : contact@jankesec.com

Pinned Loading

  1. driftnet2 driftnet2 Public

    Network traffic interception and analysis toolkit — passive recon and protocol inspection

    Go 1

  2. evilcorp-ios evilcorp-ios Public

    Intentionally vulnerable iOS application for mobile security training — 30 challenges across OWASP MASVS categories

    Swift 1 1

  3. ghostlink ghostlink Public

    Covert C2 channel over legitimate platforms — stealthy command and control for authorized red team ops

    Go 1

  4. mcpbait mcpbait Public

    Red teaming framework that proves whether an MCP-speaking agent can be hijacked by a malicious server

    Python 1

  5. macharden macharden Public

    Modern macOS Security Hardening, Audit & Remediation Engine (50 CIS/NIST/MITRE controls, Baseline Drift Engine, OASIS SARIF v2.1.0)

    Shell