awesome-repositories.com
Blog
awesome-repositories.com

Descubre los mejores repositorios open-source con nuestra búsqueda potenciada por IA.

ExplorarBúsquedas curadasAlternativas open-sourceSoftware autohospedableBlogMapa del sitio
ProyectoAcerca deCómo clasificamosPrensaServidor MCP
Aviso legalPrivacidadTérminos
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
·
danielmiessler avatar

danielmiessler/SecLists

0
View on GitHub↗
71,596 estrellas·25,032 forks·PHP·MIT·22 vistaswww.owasp.org/index.php/OWASP_Internet_of_Things_Project↗

SecLists

SecLists is a centralized library of security assessment data designed to support vulnerability discovery and penetration testing. It functions as a comprehensive repository of wordlists, payloads, and testing methodologies used to audit software, firmware, and internet-connected hardware for technical vulnerabilities.

The project distinguishes itself through a standardized taxonomy and a language-agnostic data format, which allows security tools to predictably ingest and utilize its assets regardless of the underlying programming environment. By decoupling raw testing data from execution logic, the repository ensures that its collections of usernames, passwords, and injection patterns remain portable and compatible with a wide range of custom auditing frameworks and automated security tools.

The collection covers a broad spectrum of security testing domains, including brute-force credential testing, web application fuzzing, and automated vulnerability scanning. It also provides structured guidance for firmware analysis and internet-connected device hardening, enabling researchers to apply consistent methodologies when identifying insecure configurations or potential system flaws.

The repository is organized as a collection of flat-file assets within a hierarchical directory structure, facilitating integration into automated security workflows.

Features

  • Vulnerability Assessment and Testing - Provides a centralized library of security assessment data for auditing software, firmware, and hardware.
  • Security Wordlists - Provides a comprehensive collection of usernames, passwords, and sensitive data patterns for security assessment.
  • Awesome List - A community-curated directory that catalogs and links out to other open-source projects, rather than a standalone tool you run yourself.
  • Web Application Security - Provides payloads and testing resources for discovering vulnerabilities in web applications.
  • Security Testing Methodologies - Provides a structured, community-vetted framework for performing comprehensive security audits.
  • IoT Security Testing Guides - Provides a structured collection of methodologies and guides for testing internet-connected hardware.
  • Credential Brute-Forcing - Provides large collections of common credentials for testing system resilience against brute-force attacks.
  • Injection Payloads - Provides extensive collections of injection payloads for testing application resilience against unexpected data.
  • Wordlists - Comprehensive collection of wordlists for security testing.
  • Fuzzing and Wordlists - Extensive collection of wordlists for HTTP methods and API endpoints.
  • Security Utilities - Comprehensive collection of security wordlists.
  • Wordlists and Payloads - Comprehensive collection of lists for security assessments.
  • Hacker Documentaries - Essential collection of lists for security testing and assessment.
  • Security Collections - Collection of wordlists for security assessment and testing.
  • Wordlists and Payloads - Comprehensive collection of lists for security assessments.
  • Security Curated Lists - Collection of wordlists for security assessments and fuzzing.
  • Attack Payloads - Extensive collection of wordlists for security assessment and penetration testing.
  • Attack Payloads and Wordlists - Collection of lists for usernames, passwords, and fuzzing payloads.
  • Credential Security - A massive collection of wordlists for security testing.
  • Fuzzing Wordlists - Comprehensive collection of lists for security testing and fuzzing.
  • Password Cracking - Comprehensive collection of lists for security assessments.
  • Penetration Testing - Collection of lists used during security assessments and testing.
  • Seguridad y privacidad - Collection of lists used for security assessments and testing.
  • Security Resources - Listed in the “Security Resources” section of the Awesome Hacking awesome list.
  • Threat Intelligence and OSINT - Comprehensive collection of lists for security assessments.
  • Vulnerability Research - Aggregates lists for security assessments and fuzzing.
  • Vulnerability Scanning - Provides pre-defined lists of attack patterns for systematic vulnerability scanning of applications and services.
  • Vulnerability Wordlists - Comprehensive collection of lists for security testing and fuzzing.
  • Web Security Testing - Comprehensive collection of wordlists for brute-forcing applications.
  • Wordlists - Comprehensive collection of security wordlists.
  • Wordlists and Enumeration - The industry-standard collection of wordlists for security testing.
  • Wordlists and Payloads - The industry-standard repository of wordlists for security assessments.
  • Fuzzing Resources - Provides a standardized library of input patterns and payloads for testing application resilience.
  • IoT Security Hardening - Provides methodologies and testing resources for hardening internet-connected hardware against insecure configurations.
  • Firmware Analysis Guides - Offers comprehensive guides for the complete lifecycle of device firmware analysis and exploitation.
  • Security Assessments - Provides methodologies for evaluating security risks and insecure configurations in connected hardware.
  • Firmware Security Methodologies - Provides structured methodologies for auditing and testing the security of embedded device firmware.
  • Static Asset Decoupling - Separates raw testing data from execution logic to ensure compatibility with diverse security tools.
  • Flat-File Storage - Organizes security assets into a portable, hierarchical directory structure of plain text files.
  • Standardized Directory Taxonomies - Maintains a consistent folder hierarchy to allow automated tools to predictably ingest testing resources.

Historial de estrellas

Gráfico del historial de estrellas de danielmiessler/seclistsGráfico del historial de estrellas de danielmiessler/seclists

Búsqueda con IA

Explora más repositorios increíbles

Describe lo que necesitas en lenguaje sencillo: la IA clasifica miles de proyectos open-source curados por relevancia.

Start searching with AI

Alternativas open-source a SecLists

Proyectos open-source similares, clasificados según cuántas características comparten con SecLists.
  • fuzzdb-project/fuzzdbAvatar de fuzzdb-project

    fuzzdb-project/fuzzdb

    8,819Ver en GitHub↗

    fuzzdb is a collection of datasets designed for web application penetration testing and dynamic fuzzing. It provides a fuzzing payload dictionary, a resource discovery wordlist, and a fault injection dataset containing corrupted Unicode, null bytes, and escape codes to trigger application crashes and logic errors. The project includes a security filter bypass list featuring polyglots and encoded strings to evade web application firewalls and input validation filters. It also provides a comprehensive web application penetration testing dataset specifically for identifying flaws such as cross-s

    PHP
    Ver en GitHub↗8,819
  • thekingofduck/fuzzdictsAvatar de TheKingOfDuck

    TheKingOfDuck/fuzzDicts

    8,355Ver en GitHub↗

    fuzzDicts is a repository of curated wordlists and dictionaries designed for web application fuzzing. It provides collections of strings and payloads used to discover hidden files, subdomains, and security vulnerabilities. The project includes specialized libraries for different security testing vectors, such as dictionaries for common request and cookie parameters, lists of common subdomain prefixes, and collections of passwords and default vendor credentials for brute-force testing. It also maintains a security payload library containing character sequences used to identify flaws like SQL i

    Pythondirectoryfuzz-testingfuzzer
    Ver en GitHub↗8,355
  • swisskyrepo/payloadsallthethingsAvatar de swisskyrepo

    swisskyrepo/PayloadsAllTheThings

    78,434Ver en GitHub↗

    This project is a comprehensive, community-sourced knowledge base designed for security professionals and researchers. It functions as a centralized repository of offensive security techniques, providing a structured collection of exploit payloads, attack vectors, and methodologies for conducting vulnerability assessments and penetration testing. The repository distinguishes itself through a cross-platform payload taxonomy that categorizes exploitation methods by vulnerability type and target environment, enabling rapid lookup during security assessments. It maintains high standards of data i

    Pythonbountybugbountybypass
    Ver en GitHub↗78,434
  • sbilly/awesome-securityAvatar de sbilly

    sbilly/awesome-security

    14,022Ver en GitHub↗

    This project is a comprehensive, curated directory of cybersecurity resources, software, and documentation designed to support system and network protection. It serves as a centralized knowledge base and index for security professionals, aggregating industry-standard practices and open-source tools across a wide range of technical domains. The repository distinguishes itself by providing a structured collection of methodologies and frameworks for security operations. It covers critical areas including threat intelligence, digital forensics, infrastructure auditing, and vulnerability assessmen

    awesome-listsecurity
    Ver en GitHub↗14,022
Ver las 30 alternativas a SecLists→

Preguntas frecuentes

¿Qué hace danielmiessler/seclists?

SecLists is a centralized library of security assessment data designed to support vulnerability discovery and penetration testing. It functions as a comprehensive repository of wordlists, payloads, and testing methodologies used to audit software, firmware, and internet-connected hardware for technical vulnerabilities.

¿Cuáles son las características principales de danielmiessler/seclists?

Las características principales de danielmiessler/seclists son: Vulnerability Assessment and Testing, Security Wordlists, Awesome List, Web Application Security, Security Testing Methodologies, IoT Security Testing Guides, Credential Brute-Forcing, Injection Payloads.

¿Qué alternativas de código abierto existen para danielmiessler/seclists?

Las alternativas de código abierto para danielmiessler/seclists incluyen: fuzzdb-project/fuzzdb — fuzzdb is a collection of datasets designed for web application penetration testing and dynamic fuzzing. It provides a… thekingofduck/fuzzdicts — fuzzDicts is a repository of curated wordlists and dictionaries designed for web application fuzzing. It provides… swisskyrepo/payloadsallthethings — This project is a comprehensive, community-sourced knowledge base designed for security professionals and researchers.… carpedm20/awesome-hacking — This project is a comprehensive, community-curated directory of cybersecurity resources, tools, and educational… sbilly/awesome-security — This project is a comprehensive, curated directory of cybersecurity resources, software, and documentation designed to… six2dez/onelistforall — OneListForAll is a wordlist aggregation pipeline and automated dictionary publisher designed for web security…