SecLists is the security tester's companion. It's a collection of multiple types of lists used during security assessments, collected in one place. List types include usernames, passwords, URLs, sensitive data patterns, fuzzing payloads, web shells, and many more.
☆72,501Jul 28, 2026Updated this week
Alternatives and similar repositories for SecLists
Users that are interested in SecLists are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- A list of useful payloads and bypass for Web Application Security and Pentest/CTF☆79,570Jul 23, 2026Updated last week
- Fast web fuzzer written in Go☆16,460Jul 19, 2026Updated last week
- PEASS - Privilege Escalation Awesome Scripts SUITE (with colors)☆20,220Updated this week
- Nuclei is a fast, customizable vulnerability scanner powered by the global security community and built on a simple YAML-based DSL, enabl…☆30,109Updated this week
- Dictionary of attack patterns and primitives for black-box application fault injection and resource discovery.☆8,965Nov 10, 2023Updated 2 years ago
- Deploy to Railway using AI coding agents - Free Credits Offer • AdUse Claude Code, Codex, OpenCode, and more. Autonomous software development now has the infrastructure to match with Railway.
- Impacket is a collection of Python classes for working with network protocols.☆15,949Updated this week
- Directory/File, DNS and VHost busting tool written in Go☆13,937Jul 24, 2026Updated last week
- In-depth attack surface mapping and asset discovery☆14,899Jul 19, 2026Updated last week
- PowerSploit - A PowerShell Post-Exploitation Framework☆13,089Aug 17, 2020Updated 5 years ago
- Nishang - Offensive PowerShell for red team, penetration testing and offensive security.☆10,017Apr 25, 2024Updated 2 years ago
- Scripted Local Linux Enumeration & Privilege Escalation Checks☆7,988Sep 6, 2023Updated 2 years ago
- GTFOBins is a curated list of Unix-like executables that can be used to bypass local security restrictions in misconfigured systems.☆13,501May 27, 2026Updated 2 months ago
- Fast subdomains enumeration tool for penetration testers☆11,010Aug 2, 2024Updated last year
- Web path scanner☆14,556Updated this week
- Deploy to Railway using AI coding agents - Free Credits Offer • AdUse Claude Code, Codex, OpenCode, and more. Autonomous software development now has the infrastructure to match with Railway.
- Metasploit Framework☆38,683Updated this week
- Fast passive subdomain enumeration tool.☆14,096Updated this week
- A collection of awesome penetration testing resources, tools and other shiny things☆26,772Jul 25, 2026Updated last week
- A swiss army knife for pentesting networks