Field kit

Wordlists & payloads

What list for which job

SecLists-style paths and common lists by use case, with tool links and example commands. Prefer smaller targeted lists before rockyou-scale noise.

Authorized testing only. Practice on systems you own, isolated labs, or targets with written permission. Unauthorized access is illegal.

34 of 34 lists

directories
~4.7K lines

SecLists common.txt

First-pass web directory and file discovery on most apps.

Typical path
/usr/share/seclists/Discovery/Web-Content/common.txt

Start here before larger lists. Low noise, high signal for labs and quick wins.

Example
ffuf -u https://target/FUZZ -w /usr/share/seclists/Discovery/Web-Content/common.txt -mc 200,301,302,403
directories
~62K lines

RAFT large directories

Deeper directory discovery after common.txt.

Typical path
/usr/share/seclists/Discovery/Web-Content/raft-large-directories.txt

Higher coverage; use rate limits on production. Prefer recursive tools carefully.

Example
feroxbuster -u https://target -w /usr/share/seclists/Discovery/Web-Content/raft-large-directories.txt --rate-limit 50
directories
~370K lines

RAFT large files

Discover files and backups by name patterns.

Typical path
/usr/share/seclists/Discovery/Web-Content/raft-large-files.txt

Pair with extensions (-e .bak,.old,.zip) for backup hunting.

directories
~220K lines

directory-list-2.3-medium

Classic DirBuster medium list still used in many courses.

Typical path
/usr/share/seclists/Discovery/Web-Content/directory-list-2.3-medium.txt

Noisy on large targets; filter by status and size.

directories
~20K lines

big.txt

Broader web content discovery beyond common.

Typical path
/usr/share/seclists/Discovery/Web-Content/big.txt

Good middle ground between common and raft-large.

api
varies by file; small-to-medium

api/actions and common API paths

Find REST-style endpoints and management routes.

Typical path
/usr/share/seclists/Discovery/Web-Content/api/api-endpoints.txt

Also try graphql.txt and swagger paths. Combine with httpx tech detect.

Example
ffuf -u https://api.target/v1/FUZZ -w /usr/share/seclists/Discovery/Web-Content/api/api-endpoints.txt -mc 200,401,403,405
api
small-medium

Swagger / OpenAPI path list

Locate API documentation and schema endpoints.

Typical path
/usr/share/seclists/Discovery/Web-Content/common-api-endpoints-mazen160.txt

Exposed swagger can reveal the entire attack surface.

subdomains
5K / 20K / 110K / 1M variants

Subdomains top 1 million

DNS and vhost brute force for subdomain discovery.

Typical path
/usr/share/seclists/Discovery/DNS/subdomains-top1million-5000.txt

Start with 5000 or 20000. Use resolvers carefully; prefer passive first.

Example
gobuster dns -d example.com -w /usr/share/seclists/Discovery/DNS/subdomains-top1million-5000.txt
subdomains
~150K lines

DNS namelist.txt

Compact DNS label list for labs and CTFs.

Typical path
/usr/share/seclists/Discovery/DNS/namelist.txt

Useful when top1million misses internal-style labels.

subdomains
large (1M+ depending on package)

combined_subdomains

Aggressive subdomain wordlist for bug bounty-style recon (authorized).

Typical path
/usr/share/seclists/Discovery/DNS/combined_subdomains.txt

Use only with good resolvers and rate discipline.

passwords
~14M lines (143MB compressed on Kali)

rockyou.txt

Default real-world password dictionary for offline cracking labs.

Typical path
/usr/share/wordlists/rockyou.txt

Decompress rockyou.txt.gz on Kali first. Too large for careless online spray.

Example
hashcat -m 0 hashes.txt /usr/share/wordlists/rockyou.txt
passwords
subset of rockyou

rockyou-75.txt subset

Shorter rockyou-derived list for quick lab cracks and demos.

Typical path
/usr/share/seclists/Passwords/Leaked-Databases/rockyou-75.txt

Faster feedback loop for teaching before full rockyou.

passwords
10K lines

darkweb2017-top10000

Modern common passwords for spray lab policy tests.

Typical path
/usr/share/seclists/Passwords/darkweb2017-top10000.txt

For authorized spray labs only — few passwords, many users, slow rate.

passwords
small

Common credentials pairs

Default and common user:pass combinations for lab services.

Typical path
/usr/share/seclists/Passwords/Common-Credentials/common-passwords-win.txt

Also browse Default-Credentials folder for vendor defaults on owned IoT.

passwords
small-medium

Default credentials (vendor)

Router, camera, and appliance default passwords on owned gear.

Typical path
/usr/share/seclists/Passwords/Default-Credentials/default-passwords.csv

Only against devices you own. Prefer changing defaults immediately after proof.

usernames
large

xato-net-10-million-usernames-dup

Username candidates for spray and enum labs.

Typical path
/usr/share/seclists/Usernames/xato-net-10-million-usernames-dup.txt

Start with Names/top-usernames-shortlist.txt for smaller jobs.

usernames
~17K lines

top-usernames-shortlist

Quick username list for CTF and small labs.

Typical path
/usr/share/seclists/Usernames/top-usernames-shortlist.txt

Includes admin, root, sa, test, and common patterns.

Example
kerbrute userenum --dc 10.10.10.10 -d lab.local /usr/share/seclists/Usernames/top-usernames-shortlist.txt
usernames
small

cirt-default-usernames

Default appliance usernames paired with default passwords.

Typical path
/usr/share/seclists/Usernames/cirt-default-usernames.txt

Use on owned IoT/router labs only.

snmp
small

SNMP community strings

Guess common SNMP read communities on network gear you may audit.

Typical path
/usr/share/seclists/Discovery/SNMP/common-snmp-community-strings.txt

SNMPv2c communities are secrets. Prefer SNMPv3. Authorized network devices only.

Example
nmap -sU -p 161 --script snmp-brute --script-args snmp-brute.communitiesdb=/usr/share/seclists/Discovery/SNMP/common-snmp-community-strings.txt TARGET
snmp
tiny

SNMP defaults (public/private)

Minimal SNMP check for public/private community.

Typical path
/usr/share/seclists/Discovery/SNMP/snmp-default.txt

Still appears on home and SMB gear far too often.

discovery
~6.5K lines

burp-parameter-names

Parameter discovery for hidden query and body fields.

Typical path
/usr/share/seclists/Discovery/Web-Content/burp-parameter-names.txt

Combine with Arjun for smarter discovery.

Example
ffuf -u 'https://target/page?FUZZ=test' -w /usr/share/seclists/Discovery/Web-Content/burp-parameter-names.txt -fs 0
api
medium

api parameter wordlists

Fuzz JSON and query parameter names on APIs.

Typical path
/usr/share/seclists/Discovery/Web-Content/api/objects.txt

Useful for BOLA/IDOR hunting after auth.

payloads
small-medium set of files

FuzzDB attack payloads (subset via SecLists)

Injection and traversal payload ideas for manual testing.

Typical path
/usr/share/seclists/Fuzzing/special-chars.txt

Prefer targeted manual payloads over blind huge fuzz on production.

payloads
small

SQLi generic payloads

Quick SQLi probe strings before sqlmap confirmation.

Typical path
/usr/share/seclists/Fuzzing/SQLi/Generic-SQLi.txt

Lab apps and authorized scope only. Validate impact carefully.

payloads
medium

XSS payload lists

Reflected/stored XSS polyglots for labs and PortSwigger drills.

Typical path
/usr/share/seclists/Fuzzing/XSS/XSS-Jhaddix.txt

Context matters more than list size; encode for HTML/JS/attr.

payloads
medium

LFI / path traversal lists

Local file inclusion and traversal testing on vulnerable labs.

Typical path
/usr/share/seclists/Fuzzing/LFI/LFI-Jhaddix.txt

Also try encoding variants and PHP wrappers on PHP labs.

other
medium

User-Agent strings

Rotate or spoof user agents when needed for authorized tests.

Typical path
/usr/share/seclists/Fuzzing/User-Agents/UserAgents.fuzz.txt

Do not use solely to evade defenses without RoE discussion.

discovery
small

QuickHits / interesting files

Find robots, backups, git, env, and other high-value files.

Typical path
/usr/share/seclists/Discovery/Web-Content/quickhits.txt

Excellent early pass before heavy recursive discovery.

directories
medium-large

WordPress content lists

Plugin/theme/path discovery on WordPress targets in scope.

Typical path
/usr/share/seclists/Discovery/Web-Content/CMS/wp-plugins.fuzz.txt

Prefer wpscan for versioned plugin intelligence when applicable.

passwords
64 rules (expands dict size)

hashcat best64.rule

Rule-based mutations on password dictionaries.

Typical path
/usr/share/hashcat/rules/best64.rule

Rules are not wordlists but multiply coverage; pair with rockyou.

Example
hashcat -m 1000 ntlm.txt /usr/share/wordlists/rockyou.txt -r /usr/share/hashcat/rules/best64.rule
passwords
varies

wiki-based password lists

Targeted wordlists when org culture maps to public words.

Typical path
/usr/share/seclists/Passwords/Wikipedia/

Also generate custom lists with CeWL from the target site.

passwords
depends on crawl

CeWL custom site words

Build org-specific password candidates from public pages.

Typical path
./cewl-output.txt (generated)

Ethical and effective for company-themed passwords in labs/engagements.

Example
cewl https://target.example -m 6 -w cewl-output.txt
discovery
small

web extensions list

File extension fuzzing for technologies in use.

Typical path
/usr/share/seclists/Discovery/Web-Content/web-extensions.txt

Use with -e or FUZZ.ext patterns based on fingerprint.

discovery
5K+

virtual host name lists

Find alternate Host headers / vhosts on shared IPs.

Typical path
/usr/share/seclists/Discovery/DNS/subdomains-top1million-5000.txt

Same lists as DNS often work for vhost; filter by response size.

Example
ffuf -u https://10.10.10.10 -H 'Host: FUZZ.example.com' -w /usr/share/seclists/Discovery/DNS/subdomains-top1million-5000.txt -fs 0