Skip to content
View kaaangumus's full-sized avatar
🌴
On vacation
🌴
On vacation

Highlights

  • Pro

Block or report kaaangumus

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
kaaangumus/README.md

Kaan Gümüş

Penetration Tester · Red Teamer · Offensive Security Practitioner

Website Focus OS


About

I focus on offensive security with a practical, hands-on mindset. My work is shaped around careful enumeration, realistic attack paths, clear documentation, and building small tools that make security testing faster.

My main areas of interest are Active Directory security, web application testing, internal pentesting, privilege escalation, lateral movement, and bug bounty recon workflows.

I like turning repeated manual work into simple tools, labs, and notes that can be reused in real assessments.


Focus Areas

Active Directory Security  ·  Web Application Security  ·  Internal Pentesting
Privilege Escalation       ·  Lateral Movement          ·  Bug Bounty Recon
Security Tooling           ·  Lab Building              ·  Practical Research

Featured Projects

Project Description Stack
palm Bug bounty subdomain recon pre-filter for live and takeover checks. Go
montana-framework Searchsploit-like local exploit search tool for Kali/Linux. Go
flask-ssti-lab Deliberately vulnerable Flask SSTI lab for local cybersecurity training. Flask
nhc Hash analysis and cracking utility for lab workflows. Python
SFounder Webshell discovery helper for authorized review scenarios. Python

How I Work

  • I prefer realistic scenarios over checklist-only testing.
  • I care about clean notes, reproducible findings, and practical impact.
  • I build small tools when a workflow becomes repetitive.
  • I use labs to understand techniques before applying them in authorized environments.
  • I keep the line clear: only test systems I own or have permission to assess.

Tech & Tools

Linux Kali Linux Go Python Flask Burp Suite Git


GitHub Snapshot

Kaan Gümüş GitHub profile details

Kaan Gümüş GitHub stats Kaan Gümüş repository languages


Contact

kaangumus.ninja

Offensive security is not just finding weaknesses. It is understanding systems deeply enough to explain risk clearly.

Pinned Loading

  1. loxs loxs Public

    Forked from coffinxp/loxs

    GUI security testing tool for SQLi, XSS, CRLF, LFI and open redirect discovery

    Python 1

  2. montana-framework montana-framework Public

    Searchsploit-like local exploit search tool for Kali/Linux

    Go 4