Skip to content
View EmreOvunc's full-sized avatar
🌏
Remotely... 🤩
🌏
Remotely... 🤩

Organizations

@SecTest-Innovera @RedSection

Block or report EmreOvunc

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Please don't include any personal information such as legal names or email addresses. Maximum 100 characters, markdown supported. This note will be visible to only you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse

Starred repositories

Showing results

Find vulnerabilities, misconfigurations, secrets, SBOM in containers, Kubernetes, code repositories, clouds and more

Go 27,343 2,610 Updated Jul 4, 2025

Checks expired domains for categorization/reputation and Archive.org history to determine good candidates for phishing and C2 domain names

Python 1,599 291 Updated Jun 6, 2024

SecLists is the security tester's companion. It's a collection of multiple types of lists used during security assessments, collected in one place. List types include usernames, passwords, URLs, se…

PHP 63,907 24,453 Updated Jul 4, 2025

🐸 Identify anything. pyWhat easily lets you identify emails, IP addresses, and more. Feed it a .pcap file or some text and it'll tell you what it is! 🧙‍♀️

Python 6,912 377 Updated Oct 31, 2023

OffensivePH - use old Process Hacker driver to bypass several user-mode access controls

C 333 42 Updated Oct 9, 2021

A Burp extension adding a passive scan check to flag parameters whose name or value may indicate a possible insertion point for SSRF or LFI.

Python 132 23 Updated Feb 19, 2021

A Python program to scrape secrets from GitHub through usage of a large repository of dorks.

Python 2,401 433 Updated Aug 3, 2024

pFuzz helps us to bypass web application firewall by using different methods at the same time.

Python 159 33 Updated Jan 9, 2021

search Google and extract results directly. skip all the click-through links and other sketchiness

Python 498 120 Updated Jul 12, 2022

Find, verify, and analyze leaked credentials

Go 19,755 1,894 Updated Jul 4, 2025

40X/HTTP bypasser in Go. Features: Verb tampering, headers, #bugbountytips, User-Agents, extensions, default credentials...

Go 1,730 290 Updated Jul 3, 2023

(Sim)ulate (Ba)zar Loader

C++ 29 3 Updated Nov 15, 2020

A default credential scanner.

Python 1,485 250 Updated Dec 26, 2021

A Powerful Subdomain Takeover Tool

Go 953 205 Updated Oct 17, 2023

A list of useful payloads and bypass for Web Application Security and Pentest/CTF

Python 67,338 15,562 Updated Jul 2, 2025

"Can I take over XYZ?" — a list of services and how to claim (sub)domains with dangling DNS records.

Python 5,234 760 Updated Feb 8, 2025

Takeover script extracts CNAME record of all subdomains at once. TakeOver saves researcher time and increase the chance of finding subdomain takeover vulnerability.

Shell 101 29 Updated Apr 7, 2023

Keyhacks is a repository which shows quick ways in which API keys leaked by a bug bounty program can be checked to see if they're valid.

5,582 1,114 Updated Aug 14, 2024

reNgine is an automated reconnaissance framework for web applications with a focus on highly configurable streamlined recon process via Engines, recon data correlation and organization, continuous …

HTML 8,006 1,224 Updated Feb 24, 2025

Defeating Windows User Account Control

C 6,855 1,370 Updated Jun 23, 2025

SecretFinder - A python script for find sensitive data (apikeys, accesstoken,jwt,..) and search anything on javascript files

Python 2,209 408 Updated May 26, 2024

A cross-platform protocol library to communicate with iOS devices

C 7,143 1,404 Updated Jun 29, 2025

Find web directories without bruteforce

Python 1,868 263 Updated Oct 29, 2023

Security Tool to Look For Interesting Files in S3 Buckets

Python 1,421 247 Updated Apr 10, 2024
Python 2,269 420 Updated Dec 8, 2023

File upload vulnerability scanner and exploitation tool.

Python 3,219 517 Updated May 8, 2025

An advanced Twitter scraping & OSINT tool written in Python that doesn't use Twitter's API, allowing you to scrape a user's followers, following, Tweets and more while evading most API limitations.

Python 16,137 2,765 Updated Feb 23, 2023

A plugin-based scanner that aids security researchers in identifying issues with several CMSs, mainly Drupal & Silverstripe.

HTML 1,340 260 Updated Jan 19, 2024

Scan for misconfigured S3 buckets across S3-compatible APIs!

Go 2,817 390 Updated Jun 2, 2025

A python script that finds endpoints in JavaScript files

Python 4,002 630 Updated Apr 13, 2024
Next