danielmiessler/SecLists resource
SecLists is the security tester's companion. It's a collection of multiple types of lists used during security assessments, collected in one place. List types include usernames, passwords, URLs, sensitive data patterns, fuzzing payloads, web shells, and many more. observed · 2026-08-28
Health v2 · maintenance only
83/100
- Activity 99
- Release rhythm 52
- Longevity 100
How is this computed?
round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-03. Adoption (stars, forks) is never an input.
- gap_med: 119.5
- age_days: 5310
- days_rel: 163
- days_push: 7
- n_releases_24m: 5
Adoption not part of the score
73106 stars · 25100 forks observed · 2026-08-28
What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-29, confidence not recorded
SecLists is a curated collection of security testing lists including usernames, passwords, URLs, sensitive data patterns, fuzzing payloads, and web shells. It is designed to be pulled onto a testing box so security testers have every type of list they may need during assessments.
Use cases
- find wordlists for brute-forcing passwords
- get fuzzing payloads for web app testing
- list of common usernames for security assessment
- directory and file discovery wordlists for dirbusting
- sensitive data patterns for scanning
- web shell samples for pentesting
- subdomain enumeration wordlists
When to choose
- you need a comprehensive, well-maintained collection of security testing lists in one place
- you are doing penetration testing, bug bounty, or CTF challenges
- you want wordlists compatible with tools like ffuf, gobuster, or hydra
When to avoid
- you need a small, targeted wordlist rather than a large multi-gigabyte repository
- you need programmatically generated or frequently auto-updated wordlists (e.g., Assetnote Wordlists)
- you are not doing security testing and just need general-purpose data lists
Facets
dataset · maturity active
security penetration-testing fuzzing osint security penetration-testing developer-tools windows cli wordlists payloads fuzzdb brute-force security-testing kali-linux linux macos
3 sources
- readme: https://github.com/danielmiessler/SecLists · fetched 2026-08-28 · 9b1f76ef2150
- homepage: https://www.owasp.org/index.php/OWASP_Internet_of_Things_Project · fetched 2026-08-28 · 3078b512fdef
- site_page: https://owasp.org/about/ · fetched 2026-08-28 · f0bbba449267
Member repositories
| Repository | Role | Health v2 |
|---|---|---|
| danielmiessler/SecLists | main | 83 |
For agents
markdown · JSON · MCP: product_card(name="danielmiessler/SecLists")
Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem