| Project | Focus | Stack |
|---|---|---|
| mcpbait | Red teaming framework for AI agents and Model Context Protocol (MCP) integrations — probes tool-use boundaries and prompt-injection paths. | Python |
| driftnet2 | High-performance packet capture and credential extractor leveraging eBPF/XDP. | Go |
| evilcorp-ios | Intentionally vulnerable iOS benchmark application mapped to OWASP MASVS v2 & MASWE. | Swift |
| ghostlink | Multi-channel Out-of-Band (OOB) covert C2 and data exfiltration framework over legitimate platforms, for authorized red team operations. | Go |
Offensive security is not about running tools. It's about understanding how systems break.
I am Sevban Dönmez. I break enterprise software, research low-level operating system boundaries, and design realistic attack paths. jankesec is my personal technical notebook — free from sponsor bias, compliance theater, and marketing noise.
Thirteen years in the field
I am currently a Senior Cyber Security Consultant at PwC Turkey, where I lead Red Team operations, complex penetration tests, and vulnerability assessments — 400+ enterprise-grade engagements and adversary simulations across critical infrastructure and global organizations over the past 13+ years. Offensive security has been both my profession and my primary intellectual obsession.
I am an official OWASP Web Security Testing Guide (WSTG) author, with contributions to the Mobile (MASTG) and AI (AITG) testing guides, and a voluntary contributor to open-source security tooling and Linux utilities.
My career started in the era of manual binary reversing, network packet inspection, and local privilege escalation primitives. Since then, the enterprise battlefield has shifted from perimeter firewalls to sprawling identity fabrics (Active Directory, Kerberos, OIDC), container virtualization boundaries, and now autonomous AI agent orchestration. While the technology stack has evolved, the fundamental question remains unchanged: what does this component actually trust, and what happens when that trust is violated?
Why jankesec exists
The security industry suffers from a severe signal-to-noise crisis. A vast majority of published content falls into two extremes: either high-level compliance checklists designed to satisfy auditors, or vendor marketing collateral wrapped in fear, uncertainty, and doubt (FUD).
Real adversaries do not care about compliance checklists or scanner scores. They search for reachable attack paths, ambient authority, and mismatched architectural assumptions.
I built jankesec to serve as an unvarnished, ad-free repository of genuine technical evidence. These are the notes I wished were available when spending sleepless nights debugging an undocumented macOS XPC entitlement check, isolating a subtle WebKit primitive lifetime issue, or mapping an elusive Kerberos unconstrained delegation route across an enterprise forest. Each publication states whether its conclusions come from public sources, static reconstruction, or controlled laboratory reproduction. Editorial review is never presented as a substitute for technical validation. Read the editorial standards.
Operating principles
Every article, casefile, and code sample published on this domain adheres to three foundational tenets:
- Evidence over speculation: An attack path is only as valid as its reproducible trace. Every note must document both the positive execution signal (how the path succeeded) and the negative control (how the defender proves it is closed without breaking operational availability).
- Primacy of operating system primitives: Frameworks, scripts, and commercial C2 platforms come and go. POSIX access controls, Mach-O code requirements, Windows security descriptors, and cryptographic handshakes remain durable. When you master how the operating system kernel and runtime enforce authority, vendor tooling becomes secondary.
- Human accountability in an AI era: Large language models are extraordinary tools for hypothesis generation, code comprehension, and log correlation. However, granting models broad ambient authority to execute live attacks is dangerous. I design deterministic capability brokers and strict decision ladders that preserve human judgment and accountability at every stage.
Selected security tooling
A few of the tools I maintain publicly, alongside the private platforms in the projects archive:
Responsible disclosure & research
I actively participate in coordinated vulnerability disclosure programs. My independent research has identified and resolved security vulnerabilities in products by Apple, Amazon, Intel, Zoom, ABB, Shell, and critical national infrastructure systems. I believe deeply in responsible disclosure: giving engineering teams reasonable timelines to remediate root causes before publishing technical analyses.
Credited CVEs across enterprise software and network appliances are tracked via TR-CERT and NVD — 4 published records at last count, with active coordinated disclosures in progress toward more. The full history, scoring provenance, and write-ups are kept current at jankesec.com/cves rather than restated here as a fixed number that would drift out of date.
Connecting & verified channels
I frequently collaborate with independent security researchers, engineering teams, and organizations tackling difficult technical problems. If you are investigating an interesting vulnerability class or want to discuss adversarial simulation, reach out directly:
