danielmiessler / SecLists
SecLists is the security tester's companion. It's a collection of multiple types of lists used during security assessments, collected in one place. List types include usernames, passwords, URLs, sensitive data patterns, fuzzing payloads, web shells, and many more.
☆60,362Updated this week
Alternatives and similar repositories for SecLists:
Users that are interested in SecLists are comparing it to the libraries listed below
- Directory/File, DNS and VHost busting tool written in Go☆10,777Updated 3 weeks ago
- Fast web fuzzer written in Go☆13,253Updated 7 months ago
- Dictionary of attack patterns and primitives for black-box application fault injection and resource discovery.☆8,353Updated last year
- In-depth attack surface mapping and asset discovery☆12,376Updated last month
- A list of public penetration test reports published by several consulting firms and academic security groups.☆8,635Updated 7 months ago
- This repository contains cutting-edge open-source security tools (OST) for a red teamer and threat hunter.☆9,245Updated 4 months ago
- Attack Surface Management Platform☆8,353Updated 3 weeks ago
- A swiss army knife for pentesting networks☆8,554Updated last year
- Fast passive subdomain enumeration tool.☆11,022Updated this week
- PEASS - Privilege Escalation Awesome Scripts SUITE (with colors)☆16,686Updated this week
- Impacket is a collection of Python classes for working with network protocols.☆13,827Updated this week
- E-mails, subdomains and names Harvester - OSINT☆11,877Updated this week
- Nishang - Offensive PowerShell for red team, penetration testing and offensive security.☆8,939Updated 9 months ago
- Web path scanner☆12,475Updated last week
- A Tool for Domain Flyovers☆5,702Updated 2 years ago
- PowerSploit - A PowerShell Post-Exploitation Framework☆12,064Updated 4 years ago
- EyeWitness is designed to take screenshots of websites, provide some server header info, and identify default credentials if possible.☆5,126Updated 3 months ago
- Fast subdomains enumeration tool for penetration testers☆10,071Updated 5 months ago
- Scripted Local Linux Enumeration & Privilege Escalation Checks☆7,164Updated last year
- Automated All-in-One OS Command Injection Exploitation Tool.☆4,701Updated this week
- Most advanced XSS scanner.☆13,547Updated 5 months ago
- Version 2 is live! Wordlists sorted by probability originally created for password generation and testing - make sure your passwords aren…☆8,791Updated last year
- Knock Subdomain Scan☆3,920Updated 2 months ago
- AutoRecon is a multi-threaded network reconnaissance tool which performs automated enumeration of services.☆5,280Updated 7 months ago
- Empire is a PowerShell and Python post-exploitation agent.☆7,521Updated 5 years ago
- Responder is a LLMNR, NBT-NS and MDNS poisoner, with built-in HTTP/SMB/MSSQL/FTP/LDAP rogue authentication server supporting NTLMv1/NTLMv…☆5,619Updated this week
- Nikto web server scanner☆8,872Updated 3 weeks ago
- The Browser Exploitation Framework Project☆10,015Updated this week
- Monitor linux processes without root permissions☆5,075Updated 2 years ago
- A list of useful payloads and bypass for Web Application Security and Pentest/CTF☆62,782Updated this week