7 个仓库
Collections of endpoints and payloads for automated API discovery.
Explore 7 awesome GitHub repositories matching part of an awesome list · Fuzzing and Wordlists. Refine with filters or upvote what's useful.
SecLists is a centralized library of security assessment data designed to support vulnerability discovery and penetration testing. It functions as a comprehensive repository of wordlists, payloads, and testing methodologies used to audit software, firmware, and internet-connected hardware for technical vulnerabilities. The project distinguishes itself through a standardized taxonomy and a language-agnostic data format, which allows security tools to predictably ingest and utilize its assets regardless of the underlying programming environment. By decoupling raw testing data from execution log
Extensive collection of wordlists for HTTP methods and API endpoints.
Potentially dangerous files
List of potentially dangerous files for security fuzzing.
OneListForAll is a wordlist aggregation pipeline and automated dictionary publisher designed for web security assessments. It collects, cleans, and merges multiple remote text repositories to create curated sets of paths, parameters, and credentials used in web fuzzing and vulnerability discovery. The project functions as a text data deduplication tool that filters noise and eliminates redundant entries using regular expressions and priority rules. It automates the end-to-end process of packaging these processed lists into compressed archives with cryptographic checksums and publishing them t
Collects and organizes large sets of words and parameters for automated API and endpoint discovery.
Automated wordlists for API route discovery and kiterunner.
The only GraphQL wordlist you'll ever need. Operations, field names, type names... Collected on more than 60k distinct GraphQL schemas.
Comprehensive wordlist for GraphQL schema and operation discovery.
Custom wordlists and API paths for security researchers.
Common API endpoints and objects for fuzzing operations.