Skip to content
View TayfurYldz's full-sized avatar

Sponsoring

@ahmtydn

Block or report TayfurYldz

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
tayfuryldz/README.md
Tayfur Yıldız Security Research · Bug Bounty · Security Automation

I build practical tooling for authorized security research: web application security, recon, validation, and low-noise automation.

LinkedIn HackerOne Bugcrowd Intigriti YesWeHack


What I work on

  • Web application security — attack surface, request/response behavior, bug bounty
  • Security automation — repeatable recon and verification
  • Research tooling — less noise, evidence attached to every finding
  • Open source — focused fixes with regression tests

Stack

Python, Bash, Linux, Git, GitHub and Docker

Daily environment: Kali Linux / WSL · Burp Suite · Nuclei · Nmap · ProjectDiscovery tooling

Projects

Fail-closed, evidence-based HTTP request minimizer for authorized security research.

Low-noise active scanner for CORS, CSRF, header injection, cache poisoning, and content-spoofing leads.

How I work

Evidence over assumptions: reproduce first, understand why, then verify.

Map the surface → Form a hypothesis → Reproduce → Validate → Keep the evidence

Authorized security research only.

Pinned Loading

  1. headerproof headerproof Public

    Fast, low-noise active scanner for CORS, CSRF, header injection, cache poisoning, and content spoofing leads

    Python 2

  2. marrow marrow Public

    Fail-closed, evidence-based HTTP request minimizer for authorized security research

    Python 1