Wordlists & payloads
What list for which job
SecLists-style paths and common lists by use case, with tool links and example commands. Prefer smaller targeted lists before rockyou-scale noise.
Authorized testing only. Practice on systems you own, isolated labs, or targets with written permission. Unauthorized access is illegal.
34 of 34 lists
SecLists common.txt
First-pass web directory and file discovery on most apps.
/usr/share/seclists/Discovery/Web-Content/common.txt
Start here before larger lists. Low noise, high signal for labs and quick wins.
ffuf -u https://target/FUZZ -w /usr/share/seclists/Discovery/Web-Content/common.txt -mc 200,301,302,403
RAFT large directories
Deeper directory discovery after common.txt.
/usr/share/seclists/Discovery/Web-Content/raft-large-directories.txt
Higher coverage; use rate limits on production. Prefer recursive tools carefully.
feroxbuster -u https://target -w /usr/share/seclists/Discovery/Web-Content/raft-large-directories.txt --rate-limit 50
RAFT large files
Discover files and backups by name patterns.
/usr/share/seclists/Discovery/Web-Content/raft-large-files.txt
Pair with extensions (-e .bak,.old,.zip) for backup hunting.
directory-list-2.3-medium
Classic DirBuster medium list still used in many courses.
big.txt
Broader web content discovery beyond common.
/usr/share/seclists/Discovery/Web-Content/big.txt
Good middle ground between common and raft-large.
api/actions and common API paths
Find REST-style endpoints and management routes.
Swagger / OpenAPI path list
Locate API documentation and schema endpoints.
Subdomains top 1 million
DNS and vhost brute force for subdomain discovery.
/usr/share/seclists/Discovery/DNS/subdomains-top1million-5000.txt
Start with 5000 or 20000. Use resolvers carefully; prefer passive first.
gobuster dns -d example.com -w /usr/share/seclists/Discovery/DNS/subdomains-top1million-5000.txt
DNS namelist.txt
Compact DNS label list for labs and CTFs.
/usr/share/seclists/Discovery/DNS/namelist.txt
Useful when top1million misses internal-style labels.
combined_subdomains
Aggressive subdomain wordlist for bug bounty-style recon (authorized).
/usr/share/seclists/Discovery/DNS/combined_subdomains.txt
Use only with good resolvers and rate discipline.
rockyou.txt
Default real-world password dictionary for offline cracking labs.
/usr/share/wordlists/rockyou.txt
Decompress rockyou.txt.gz on Kali first. Too large for careless online spray.
hashcat -m 0 hashes.txt /usr/share/wordlists/rockyou.txt
rockyou-75.txt subset
Shorter rockyou-derived list for quick lab cracks and demos.
/usr/share/seclists/Passwords/Leaked-Databases/rockyou-75.txt
Faster feedback loop for teaching before full rockyou.
darkweb2017-top10000
Modern common passwords for spray lab policy tests.
/usr/share/seclists/Passwords/darkweb2017-top10000.txt
For authorized spray labs only — few passwords, many users, slow rate.
Common credentials pairs
Default and common user:pass combinations for lab services.
/usr/share/seclists/Passwords/Common-Credentials/common-passwords-win.txt
Also browse Default-Credentials folder for vendor defaults on owned IoT.
Default credentials (vendor)
Router, camera, and appliance default passwords on owned gear.
/usr/share/seclists/Passwords/Default-Credentials/default-passwords.csv
Only against devices you own. Prefer changing defaults immediately after proof.
xato-net-10-million-usernames-dup
Username candidates for spray and enum labs.
/usr/share/seclists/Usernames/xato-net-10-million-usernames-dup.txt
Start with Names/top-usernames-shortlist.txt for smaller jobs.
top-usernames-shortlist
Quick username list for CTF and small labs.
cirt-default-usernames
Default appliance usernames paired with default passwords.
SNMP community strings
Guess common SNMP read communities on network gear you may audit.
/usr/share/seclists/Discovery/SNMP/common-snmp-community-strings.txt
SNMPv2c communities are secrets. Prefer SNMPv3. Authorized network devices only.
nmap -sU -p 161 --script snmp-brute --script-args snmp-brute.communitiesdb=/usr/share/seclists/Discovery/SNMP/common-snmp-community-strings.txt TARGET
SNMP defaults (public/private)
Minimal SNMP check for public/private community.
/usr/share/seclists/Discovery/SNMP/snmp-default.txt
Still appears on home and SMB gear far too often.
burp-parameter-names
Parameter discovery for hidden query and body fields.
/usr/share/seclists/Discovery/Web-Content/burp-parameter-names.txt
Combine with Arjun for smarter discovery.
ffuf -u 'https://target/page?FUZZ=test' -w /usr/share/seclists/Discovery/Web-Content/burp-parameter-names.txt -fs 0
api parameter wordlists
Fuzz JSON and query parameter names on APIs.
FuzzDB attack payloads (subset via SecLists)
Injection and traversal payload ideas for manual testing.
/usr/share/seclists/Fuzzing/special-chars.txt
Prefer targeted manual payloads over blind huge fuzz on production.
SQLi generic payloads
Quick SQLi probe strings before sqlmap confirmation.
/usr/share/seclists/Fuzzing/SQLi/Generic-SQLi.txt
Lab apps and authorized scope only. Validate impact carefully.
XSS payload lists
Reflected/stored XSS polyglots for labs and PortSwigger drills.
/usr/share/seclists/Fuzzing/XSS/XSS-Jhaddix.txt
Context matters more than list size; encode for HTML/JS/attr.
LFI / path traversal lists
Local file inclusion and traversal testing on vulnerable labs.
/usr/share/seclists/Fuzzing/LFI/LFI-Jhaddix.txt
Also try encoding variants and PHP wrappers on PHP labs.
User-Agent strings
Rotate or spoof user agents when needed for authorized tests.
/usr/share/seclists/Fuzzing/User-Agents/UserAgents.fuzz.txt
Do not use solely to evade defenses without RoE discussion.
QuickHits / interesting files
Find robots, backups, git, env, and other high-value files.
WordPress content lists
Plugin/theme/path discovery on WordPress targets in scope.
hashcat best64.rule
Rule-based mutations on password dictionaries.
/usr/share/hashcat/rules/best64.rule
Rules are not wordlists but multiply coverage; pair with rockyou.
hashcat -m 1000 ntlm.txt /usr/share/wordlists/rockyou.txt -r /usr/share/hashcat/rules/best64.rule
wiki-based password lists
Targeted wordlists when org culture maps to public words.
/usr/share/seclists/Passwords/Wikipedia/
Also generate custom lists with CeWL from the target site.
CeWL custom site words
Build org-specific password candidates from public pages.
./cewl-output.txt (generated)
Ethical and effective for company-themed passwords in labs/engagements.
cewl https://target.example -m 6 -w cewl-output.txt
web extensions list
File extension fuzzing for technologies in use.
/usr/share/seclists/Discovery/Web-Content/web-extensions.txt
Use with -e or FUZZ.ext patterns based on fingerprint.
virtual host name lists
Find alternate Host headers / vhosts on shared IPs.