Skip to content
View EmreOvunc's full-sized avatar
🌏
Remotely... 🤩
🌏
Remotely... 🤩

Organizations

@SecTest-Innovera @RedSection

Block or report EmreOvunc

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Please don't include any personal information such as legal names or email addresses. Maximum 100 characters, markdown supported. This note will be visible to only you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse

Starred repositories

Showing results

Find vulnerabilities, misconfigurations, secrets, SBOM in containers, Kubernetes, code repositories, clouds and more

Go 26,836 2,560 Updated May 22, 2025

Checks expired domains for categorization/reputation and Archive.org history to determine good candidates for phishing and C2 domain names

Python 1,593 289 Updated Jun 6, 2024

SecLists is the security tester's companion. It's a collection of multiple types of lists used during security assessments, collected in one place. List types include usernames, passwords, URLs, se…

PHP 62,958 24,353 Updated May 22, 2025

🐸 Identify anything. pyWhat easily lets you identify emails, IP addresses, and more. Feed it a .pcap file or some text and it'll tell you what it is! 🧙‍♀️

Python 6,891 374 Updated Oct 31, 2023

OffensivePH - use old Process Hacker driver to bypass several user-mode access controls

C 332 42 Updated Oct 9, 2021

A Burp extension adding a passive scan check to flag parameters whose name or value may indicate a possible insertion point for SSRF or LFI.

Python 132 23 Updated Feb 19, 2021

A Python program to scrape secrets from GitHub through usage of a large repository of dorks.

Python 2,383 431 Updated Aug 3, 2024

pFuzz helps us to bypass web application firewall by using different methods at the same time.

Python 158 33 Updated Jan 9, 2021

search Google and extract results directly. skip all the click-through links and other sketchiness

Python 499 120 Updated Jul 12, 2022

Find, verify, and analyze leaked credentials

Go 19,157 1,849 Updated May 22, 2025

40X/HTTP bypasser in Go. Features: Verb tampering, headers, #bugbountytips, User-Agents, extensions, default credentials...

Go 1,713 292 Updated Jul 3, 2023

(Sim)ulate (Ba)zar Loader

C++ 29 3 Updated Nov 15, 2020

A default credential scanner.

Python 1,482 251 Updated Dec 26, 2021

A Powerful Subdomain Takeover Tool

Go 951 203 Updated Oct 17, 2023

A list of useful payloads and bypass for Web Application Security and Pentest/CTF

Python 65,564 15,375 Updated May 22, 2025

"Can I take over XYZ?" — a list of services and how to claim (sub)domains with dangling DNS records.

Python 5,180 748 Updated Feb 8, 2025

Takeover script extracts CNAME record of all subdomains at once. TakeOver saves researcher time and increase the chance of finding subdomain takeover vulnerability.

Shell 101 29 Updated Apr 7, 2023

Keyhacks is a repository which shows quick ways in which API keys leaked by a bug bounty program can be checked to see if they're valid.

5,502 1,102 Updated Aug 14, 2024

reNgine is an automated reconnaissance framework for web applications with a focus on highly configurable streamlined recon process via Engines, recon data correlation and organization, continuous …

HTML 7,925 1,204 Updated Feb 24, 2025

Defeating Windows User Account Control

C 6,764 1,355 Updated Mar 9, 2025

SecretFinder - A python script for find sensitive data (apikeys, accesstoken,jwt,..) and search anything on javascript files

Python 2,176 405 Updated May 26, 2024

A cross-platform protocol library to communicate with iOS devices

C 7,020 1,384 Updated Feb 28, 2025

Find web directories without bruteforce

Python 1,833 258 Updated Oct 29, 2023

Security Tool to Look For Interesting Files in S3 Buckets

Python 1,413 245 Updated Apr 10, 2024
Python 2,261 419 Updated Dec 8, 2023

File upload vulnerability scanner and exploitation tool.

Python 3,203 512 Updated May 8, 2025

An advanced Twitter scraping & OSINT tool written in Python that doesn't use Twitter's API, allowing you to scrape a user's followers, following, Tweets and more while evading most API limitations.

Python 16,083 2,760 Updated Feb 23, 2023

A plugin-based scanner that aids security researchers in identifying issues with several CMSs, mainly Drupal & Silverstripe.

HTML 1,331 260 Updated Jan 19, 2024

Scan for misconfigured S3 buckets across S3-compatible APIs!

Go 2,777 387 Updated May 5, 2025

A python script that finds endpoints in JavaScript files

Python 3,954 624 Updated Apr 13, 2024
Next