Senior Cyber Security Consultant at PwC specializing in offensive security, vulnerability research, and penetration testing. Over 13+ years of offensive experience, having conducted 400+ enterprise-grade penetration tests and uncovered 100+ zero-day vulnerabilities across critical infrastructure and enterprise platforms.
Official OWASP Author (WSTG) · Contributor to Mobile (MASTG) & AI (AITG) Standards.
Research & CVEs · Field Notes · Projects · PGP Key
- Vulnerability Research: Broad-spectrum vulnerability discovery, reverse engineering, and responsible disclosure across diverse software architectures, protocols, and enterprise bug bounty programs.
- Offensive Security: Comprehensive adversary simulation, end-to-end red team operations, and offensive capability development across modern enterprise defense perimeters.
- Penetration Testing: Full-scope penetration testing spanning web & mobile applications, internal/external networks, cloud environments, APIs, and enterprise identity infrastructures.
| Project | Focus | Stack |
|---|---|---|
| mcpbait | Red teaming framework for AI agents and Model Context Protocol (MCP) integrations. | Python |
| driftnet2 | High-performance packet capture and credential extractor leveraging eBPF/XDP. | Go, eBPF |
| evilcorp-ios | Intentionally vulnerable iOS benchmark application mapped to OWASP MASVS v2 & MASWE. | Swift |
| ghostlink | Multi-channel Out-of-Band (OOB) covert C2 and data exfiltration framework. | Go |
- OWASP Foundation: Official Author of the Web Security Testing Guide (WSTG), with active contributions across the AI Testing Guide (AITG) and Mobile Application Security Testing Guide (MASTG).
- Open Source Ecosystem & Tooling: Active voluntary contributor dedicated to supporting and securing the open-source community, with upstream contributions across ProjectDiscovery, security frameworks, and Linux utilities.
- Vulnerability Research & Bug Bounty: Author of credited CVEs across enterprise software and network appliances (tracked via TR-CERT & NVD), with a proven responsible disclosure track record across enterprise bug bounty programs. Disclosures and write-ups published at jankesec.com/cves.
Coordinated disclosures and signed communications:
Identity : Sevban Dönmez (jankesec)
PGP Fingerprint : FF0A 7D83 6751 CCE3 F9CC F574 FCF8 39FB 7F00 4626
Key ID : 5FDB257F4AAE8C3F
Public Key : https://jankesec.com/pgp-key.txt
Verification : https://jankesec.com/pgp/
Signed Comms : contact@jankesec.com