Wordlists
The discovery wordlists worth having, each with a one-line fetch command.
Wordlists index
- SecLists - The single most useful collection: discovery, fuzzing, passwords, usernames, payloads. If you install one thing, install this.
- subdomains-top1million-5000.txt - Top 5k subdomain labels. Fast first-pass DNS bruteforce.
- best-dns-wordlist.txt (Assetnote) - Assetnote's curated DNS wordlist built from real internet data. The go-to for serious subdomain bruteforcing.
- directory-list-2.3-medium.txt - The classic DirBuster medium list for directory/file discovery. Balanced size and coverage.
- raft-medium-directories.txt - RAFT lists are ordered by real-world frequency, so hits come early. Great default for ffuf/feroxbuster.
- OneListForAll - Six2dez's merged, deduped content-discovery megalist. One list to rule directory fuzzing.
- httparchive_apiroutes (Assetnote) - API routes and endpoints mined from the HTTP Archive. Excellent for finding hidden API surface.
- rockyou.txt - The legendary leaked password list. Baseline for password spraying/cracking exercises.
- resolvers.txt (Trickest) - Frequently-updated list of validated public DNS resolvers for puredns/shuffledns. Stale resolvers ruin bruteforce accuracy - refresh often.
- raft-medium-files.txt - Frequency-ordered file names (not directories). Pair with raft-medium-directories. Hits .bak, .old, .map, .json early.
- raft-large-directories.txt - Larger RAFT directory list for when the medium list went quiet and the target is worth the extra noise.
- common-api-endpoints.txt - Short, high-signal API path list (swagger, graphql, internal, v1/v2, admin). Use with ffuf -mc 200,401,403.
- spring-boot.txt - Actuator and Spring paths. /actuator/env and heapdump still land on forgotten profiles.
- well-known.txt - RFC 8615 well-known paths: oauth, openid, security.txt, change-password, assetlinks, jwks. Hit every host.
- burp-parameter-names.txt - Classic parameter-name list for Arjun/x8/ffuf when you need extra keys on an interesting endpoint.
- subdomains-top1million-20000.txt - Top 20k subdomain labels. The step up from the 5k list when the first pass was thin.
- all.txt (Jhaddix) - The famous mega content list. Huge and noisy. Use on a single juicy host, not across 3k subdomains.
- graphql.txt - GraphQL paths and field names for when introspection is off and you are guessing the route.
- Assetnote automated wordlists - Technology-specific lists mined from HTTP Archive (IIS, Tomcat, nginx, APIs). Pick the list that matches httpx tech-detect.
- jwt-secrets wordlists - Weak HMAC secrets used to test alg confusion and HS256-with-public-key. Only against tokens you minted or a program that allows JWT tests.
- subdomains-top1million-110000.txt - Top 110k subdomain labels from SecLists. The step up from the 5k and 20k lists when a first pass was thin.
- dns-Jhaddix.txt - Long subdomain label list in SecLists Discovery/DNS. This is not the separate Jhaddix content-discovery gist.
- bitquark-subdomains-top100000.txt - Bitquark top 100k subdomain labels, as shipped in SecLists. Useful as another passive bruteforce source beside the top-1m cuts.
- common.txt - The short classic dirb common wordlist, copied into SecLists Web-Content. A fast first pass on one host before a larger RAFT list.
- raft-large-files.txt - Frequency-ordered file names from the large RAFT set. Use it when raft-medium-files went quiet on a host that is still worth the extra requests.
- api-endpoints.txt - Short API path list at SecLists Discovery/Web-Content/api/api-endpoints.txt. Separate from the mazen160 common-api-endpoints file already in the catalog.