Skip to content
View EmreOvunc's full-sized avatar
🌏
Remotely... 🤩
🌏
Remotely... 🤩

Organizations

@SecTest-Innovera @RedSection

Block or report EmreOvunc

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Please don't include any personal information such as legal names or email addresses. Maximum 100 characters, markdown supported. This note will be visible to only you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse

Starred repositories

Showing results

Find vulnerabilities, misconfigurations, secrets, SBOM in containers, Kubernetes, code repositories, clouds and more

Go 25,212 2,471 Updated Mar 29, 2025

Checks expired domains for categorization/reputation and Archive.org history to determine good candidates for phishing and C2 domain names

Python 1,582 291 Updated Jun 6, 2024

SecLists is the security tester's companion. It's a collection of multiple types of lists used during security assessments, collected in one place. List types include usernames, passwords, URLs, se…

PHP 61,729 24,235 Updated Mar 30, 2025

🐸 Identify anything. pyWhat easily lets you identify emails, IP addresses, and more. Feed it a .pcap file or some text and it'll tell you what it is! 🧙‍♀️

Python 6,832 368 Updated Oct 31, 2023

OffensivePH - use old Process Hacker driver to bypass several user-mode access controls

C 330 42 Updated Oct 9, 2021

A Burp extension adding a passive scan check to flag parameters whose name or value may indicate a possible insertion point for SSRF or LFI.

Python 131 23 Updated Feb 19, 2021

A Python program to scrape secrets from GitHub through usage of a large repository of dorks.

Python 2,359 427 Updated Aug 3, 2024

pFuzz helps us to bypass web application firewall by using different methods at the same time.

Python 158 33 Updated Jan 9, 2021

search Google and extract results directly. skip all the click-through links and other sketchiness

Python 498 120 Updated Jul 12, 2022

Find, verify, and analyze leaked credentials

Go 18,624 1,813 Updated Mar 28, 2025

40X/HTTP bypasser in Go. Features: Verb tampering, headers, #bugbountytips, User-Agents, extensions, default credentials...

Go 1,691 291 Updated Jul 3, 2023

(Sim)ulate (Ba)zar Loader

C++ 29 3 Updated Nov 15, 2020

A default credential scanner.

Python 1,476 250 Updated Dec 26, 2021

A Powerful Subdomain Takeover Tool

Go 942 204 Updated Oct 17, 2023

A list of useful payloads and bypass for Web Application Security and Pentest/CTF

Python 64,263 15,188 Updated Mar 27, 2025

"Can I take over XYZ?" — a list of services and how to claim (sub)domains with dangling DNS records.

Python 5,085 743 Updated Feb 8, 2025

Takeover script extracts CNAME record of all subdomains at once. TakeOver saves researcher time and increase the chance of finding subdomain takeover vulnerability.

Shell 101 29 Updated Apr 7, 2023

Keyhacks is a repository which shows quick ways in which API keys leaked by a bug bounty program can be checked to see if they're valid.

5,396 1,087 Updated Aug 14, 2024

reNgine is an automated reconnaissance framework for web applications with a focus on highly configurable streamlined recon process via Engines, recon data correlation and organization, continuous …

HTML 7,815 1,184 Updated Feb 24, 2025

Defeating Windows User Account Control

C 6,669 1,338 Updated Mar 9, 2025

SecretFinder - A python script for find sensitive data (apikeys, accesstoken,jwt,..) and search anything on javascript files

Python 2,129 397 Updated May 26, 2024

A cross-platform protocol library to communicate with iOS devices

C 6,937 1,364 Updated Feb 28, 2025

Find web directories without bruteforce

Python 1,818 258 Updated Oct 29, 2023

Security Tool to Look For Interesting Files in S3 Buckets

Python 1,394 245 Updated Apr 10, 2024
Python 2,253 418 Updated Dec 8, 2023

File upload vulnerability scanner and exploitation tool.

Python 3,181 509 Updated Apr 16, 2023

An advanced Twitter scraping & OSINT tool written in Python that doesn't use Twitter's API, allowing you to scrape a user's followers, following, Tweets and more while evading most API limitations.

Python 16,004 2,753 Updated Feb 23, 2023

A plugin-based scanner that aids security researchers in identifying issues with several CMSs, mainly Drupal & Silverstripe.

HTML 1,323 258 Updated Jan 19, 2024

Scan for misconfigured S3 buckets across S3-compatible APIs!

Go 2,720 383 Updated Mar 17, 2025

A python script that finds endpoints in JavaScript files

Python 3,880 615 Updated Apr 13, 2024
Next
Showing results