Security mailing list archive for the Nmap lists, Bugtraq, Full Disclosure, Security Basics, Pen-test, and dozens more. Search capabilities and RSS feeds with smart excerpts are available
SecLists is the security tester's companion. It's a collection of multiple types of lists used during security assessments, collected in one place. List types include usernames, passwords, URLs, sensitive data patterns, fuzzing payloads, web shells, and many more. The goal is to enable a security tester to pull this repository onto a new testing box and have access to every type of list that might be needed.
3000 / day
5000 / day
3.5 pages per visit
Domain Rating
Domain Authority
Citation Level
English, etc
Offers a wide-ranging collection of lists for various security testing purposes.
Includes lists of common and default usernames used in security assessments.
Contains lists of common, default, and breached passwords for testing password strength.
Provides payloads for fuzzing applications to discover vulnerabilities.
Includes a variety of web shells for testing web application security.
Offers patterns for identifying sensitive data in applications.
Contains lists of URLs for testing web application security.
The project is open source, allowing for community contributions and updates.
The lists are regularly updated to include new data and remove outdated information.
Encourages contributions from the security community to expand and improve the lists.
SecLists is released under the MIT License, allowing for wide use and modification.
The project is hosted on GitHub, facilitating easy access and contribution.
SecLists is widely used by security professionals and penetration testers around the world.
The project welcomes contributions from the community to help improve and expand the lists.
Comprehensive documentation is available to help users understand and utilize the lists effectively.
Security headers report is a very important part of user data protection. Learn more about http headers for seclists.org