# ihebski/DefaultCreds-cheat-sheet

One place for all the default credentials to assist the Blue/Red teamers identifying devices with default password 🛡️

Repository: https://github.com/ihebski/DefaultCreds-cheat-sheet
Canonical: https://ross.abutalabs.com/products/defaultcreds-cheat-sheet
Homepage: https://pypi.org/project/DefaultCreds_cheat_sheet/
Language: Python
License: MIT
License Family: permissive
Topics: infosec, default-password, pentesting, bugbounty, pentest, cheatsheet, cybersecurity, blueteam, offensive-security, exploit, blueteam-tools, blueteaming, offensive-security-projects, soc
Last push: 2026-07-09T10:09:24+00:00

## Health v2 (maintenance only)
Score: 64/100 (v2, computed 2026-09-03T02:20:16.233290+00:00)
- activity 91, release rhythm 8, longevity 100
- inputs: {"age_days": 2070, "days_push": 55, "days_rel": 543, "gap_med": null, "n_releases_24m": 1}
- flags: none
- formula: round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)

## Adoption (not part of the score)
Stars 6725, forks 784 (observed 2026-08-28T04:09:48.083821+00:00)

## What it is
A searchable dataset and CLI tool aggregating default usernames and passwords for thousands of products and vendors, sourced from projects like changeme, routersploit, and SecLists. It helps pentesters find default credentials during engagements and blue teams identify devices that still use factory passwords.

## Use cases
- look up default credentials for tomcat or other products during a pentest
- find devices on the network still using factory default passwords
- search default login password pairs for a vendor
- audit company infrastructure for default credential vulnerabilities
- get a default password list for bug bounty recon

## When to choose
- you need a quick CLI lookup of default creds for a specific product
- you want a curated, regularly updated dataset of vendor default credentials
- you're doing OWASP WSTG-ATHN-02 default credential testing

## When to avoid
- you need automated credential spraying against live targets - use changeme or routersploit instead
- you need brute-forcing or password cracking rather than known default credentials

## Facets
- artifact type: dataset
- maturity: active
- function: search-engine, security, cli
- domain: security, penetration-testing, developer-tools
- platform: windows, cli, python
- tags: default-credentials, cheat-sheet, pentesting, red-team, blue-team, password-database, bugbounty, linux, macos

## Member repositories
- ihebski/DefaultCreds-cheat-sheet (main) score 64

## Provenance
- Observed fields: from GitHub, fetched 2026-08-28T04:09:48.083821+00:00.
- Health v2: computed from the inputs above; adoption is never an input.
- Inferred fields (summary, facets, guidance): AI-extracted, prompt v1, taxonomy v1, on 2026-08-29T17:42:53.981124+00:00, confidence not recorded.
  - readme: https://github.com/ihebski/DefaultCreds-cheat-sheet (fetched 2026-08-28T04:09:48.083821+00:00, sha 4c68a2e90d7d)
  - homepage: https://pypi.org/project/DefaultCreds_cheat_sheet/ (fetched 2026-08-29T08:38:52.932533+00:00, sha 4b4e8fead74a)
  - registry_pypi: https://pypi.org/pypi/defaultcreds-cheat-sheet/json (fetched 2026-08-29T08:38:52.941575+00:00, sha 5498719b1c19)
- Data as of 2026-08-30T08:39:29.467469+00:00.
