Skip to content
View jankesec's full-sized avatar

Block or report jankesec

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
jankesec/README.md

Sevban Dönmez

Senior Cyber Security Consultant at PwC with 5+ years of corporate experience specializing in offensive security, vulnerability research, and penetration testing. Backed by 14+ years of hands-on security research, I have conducted more than 400 enterprise-grade penetration tests and discovered over 100 zero-day vulnerabilities across critical infrastructure and enterprise environments.

Official OWASP Author (WSTG) · Contributor to Mobile (MASTG) & AI (AITG) Standards.

Research & CVEs · Field Notes · Projects · PGP Key


Focus Areas

  • Vulnerability Research: Broad-spectrum vulnerability discovery, reverse engineering, and responsible disclosure across diverse software architectures, protocols, and enterprise bug bounty programs.
  • Offensive Security: Comprehensive adversary simulation, end-to-end red team operations, and offensive capability development across modern enterprise defense perimeters.
  • Penetration Testing: Full-scope penetration testing spanning web & mobile applications, internal/external networks, cloud environments, APIs, and enterprise identity infrastructures.

Selected Security Tooling

Project Focus Stack Popularity
macharden Enterprise-grade macOS security audit, baseline drift & hardening engine (54 CIS/NIST controls, OASIS SARIF v2.1.0, Liquid Glass HTML5, zero dependencies). Zsh, Bash Stars
mcpbait Adversarial red-teaming framework for AI agents & Model Context Protocol (MCP) servers (13 MITRE ATLAS modules, canary traps, memory & schema poisoning). Python, FastMCP Stars
driftnet2 High-performance network packet capture, passive recon, protocol dissection & credential extractor leveraging eBPF/XDP. Go, eBPF, C Stars
evilcorp-ios Intentionally vulnerable iOS benchmark application mapped to OWASP MASVS v2 & MASWE. Swift Stars
ghostlink Multi-channel Out-of-Band (OOB) covert C2 and data exfiltration framework. Go Stars

Ecosystem Contributions & Disclosures

  • OWASP Foundation: Official Author of the Web Security Testing Guide (WSTG), with active contributions across the AI Testing Guide (AITG) and Mobile Application Security Testing Guide (MASTG).
  • Open Source Ecosystem & Tooling: Active voluntary contributor dedicated to supporting and securing the open-source community, with upstream contributions across ProjectDiscovery, security frameworks, and Linux utilities.
  • Vulnerability Research & Bug Bounty: Author of credited CVEs across enterprise software and network appliances (tracked via TR-CERT & NVD), with a proven responsible disclosure track record across enterprise bug bounty programs. Disclosures and write-ups published at jankesec.com/cves.

Cryptographic Identity & Contact

Coordinated disclosures and signed communications:

Identity        : Sevban Dönmez (jankesec)
PGP Fingerprint : FF0A 7D83 6751 CCE3 F9CC F574 FCF8 39FB 7F00 4626
Key ID          : 5FDB257F4AAE8C3F
Public Key      : https://jankesec.com/pgp-key.txt
Verification    : https://jankesec.com/pgp/
Signed Comms    : contact@jankesec.com

@jankesec's activity is private