SecLists Password Wordlists for Penetration Testing: Structure, Usage, and Examples

SecLists is a curated, community-maintained repository containing over 500 wordlists—including the legendary rockyou.txt—that security professionals feed directly into tools like Hashcat, Hydra, and ffuf during penetration testing and red-team engagements.

SecLists, maintained by Daniel Miessler and the open-source security community, serves as the de-facto standard for SecLists password wordlists for penetration testing. Released under the Creative Commons Attribution-ShareAlike 4.0 International (CC-BY-SA-4.0) license, this repository organizes millions of credentials, payloads, and fuzzing vectors into thematic directories that practitioners mount at /usr/share/wordlists/ on Kali Linux and Parrot OS.

Core Repository Architecture

The repository root contains thematic folders designed for immediate consumption by offensive security tools. Each directory holds plain-text files (or compressed archives) that require no preprocessing before use.

The Passwords/ Directory

The Passwords/ folder contains the flagship SecLists password wordlists for penetration testing, sorted by source, length, and theme. Key files include:

  • Passwords/rockyou.txt – A 14-million-entry classic compiled from the 2009 RockYou breach, the industry standard for credential cracking.
  • Passwords/top-20-most-common.txt – A lightweight list containing the twenty most frequently observed passwords for rapid initial testing.
  • Passwords/darkc0de.txt – A curated list from the darkc0de community, optimized for dictionary attacks against common applications.

The Usernames/ Directory

The Usernames/ collection provides harvested credentials from public breaches and default device accounts. The primary file Usernames/xato-net-10-million-usernames.txt contains ten million unique usernames derived from real-world compromise data, ideal for credential-stuffing campaigns.

Fuzzing, Payloads, and Pattern Matching

Beyond credentials, the repository includes:

  • Fuzzing/ – Injection payloads for XSS, SSRF, command injection, and directory traversal (e.g., Fuzzing/file-extensions.txt for extension enumeration).
  • Payloads/ – Ready-made exploit scenarios such as Zip-Traversal archives.
  • Pattern-Matching/ – Regex-friendly strings for static analysis tools.
  • .bin/wordlist-updaters/updater.py – A maintenance script that synchronizes selected wordlists with upstream sources to ensure fresh data.

Using SecLists Password Wordlists with Common Tools

Password Cracking with Hashcat

Feed rockyou.txt directly into Hashcat as a candidate password source. The file path assumes a standard Kali Linux installation:

hashcat -a 0 -m 1000 -w 3 -O \
    /usr/share/wordlists/SecLists/Passwords/rockyou.txt \
    hashes.txt

Credential Stuffing with Hydra

Pair username lists with password lists to attack SSH, RDP, or web login forms:

hydra -L /usr/share/wordlists/SecLists/Usernames/xato-net-10-million-usernames.txt \
      -P /usr/share/wordlists/SecLists/Passwords/top-20-most-common.txt \
      ssh://target.host

Web Enumeration with ffuf

Use SecLists for directory and file brute-forcing:

ffuf -u https://example.com/FUZZ \
     -w /usr/share/wordlists/SecLists/Fuzzing/file-extensions.txt \
     -mc 200,403

Custom Python Automation

Load wordlists into custom scripts using standard file I/O:

with open("/usr/share/wordlists/SecLists/Passwords/darkc0de.txt", "r", encoding="utf-8") as f:
    passwords = [line.strip() for line in f if line.strip()]

for pwd in passwords:
    try_login(user="admin", password=pwd)

Windows PowerShell Integration

For credential spraying from Windows environments:

$users = Get-Content "C:\SecLists\Usernames\top-usernames-shortlist.txt"
$pwd = "Password123!"
foreach ($u in $users) {
    # Insert authentication logic here

    Test-ADCredential -Username $u -Password $pwd
}

Automating Wordlist Maintenance

The repository includes CONTRIBUTING.md and README.md at the root level, documenting formatting rules and submission guidelines. For environments requiring updated lists, the .bin/wordlist-updaters/updater.py script automates synchronization with upstream sources, ensuring that frequently rotated lists (like the RockYou mirror) remain current without manual intervention.

Summary

  • SecLists provides Passwords/rockyou.txt and millions of other entries organized under the CC-BY-SA-4.0 license.
  • The repository structure separates credentials (Passwords/, Usernames/) from attack payloads (Fuzzing/, Payloads/) for efficient tool integration.
  • Tools including Hashcat, Hydra, ffuf, John the Ripper, and Burp Suite consume these files directly via standard file paths or stdin piping.
  • Maintenance scripts in .bin/wordlist-updaters/ support automated updates for continuously evolving wordlists.

Frequently Asked Questions

The Passwords/rockyou.txt file remains the most widely used list, containing approximately 14 million unique passwords from the 2009 RockYou data breach. According to the Passwords/README.md, this list serves as the baseline dictionary for most brute-force attacks due to its high success rate against common user passwords.

How do I install SecLists on Kali Linux?

Kali Linux includes SecLists in its default repository. Install via apt install seclists to mount the collection at /usr/share/wordlists/SecLists/. Alternatively, clone directly from danielmiessler/SecLists on GitHub and symlink the directory to your preferred path.

Can I use SecLists wordlists commercially?

Yes. The LICENSE file specifies Creative Commons Attribution-ShareAlike 4.0 International, which permits commercial use, modification, and distribution provided you attribute the original authors and share derivatives under the same license terms.

How often are the password wordlists updated?

Update frequency varies by list. High-value targets like rockyou.txt receive periodic refreshes via the .bin/wordlist-updaters/updater.py utility, while community submissions follow the pull-request workflow documented in CONTRIBUTING.md. Critical bug fixes and new breach data typically merge within days of submission.

Have a question about this repo?

These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:

Share the following with your agent to get started:
curl -s "https://instagit.com/install.md"

Works with
Claude Codex Cursor VS Code OpenClaw Any MCP Client

Maintain an open-source project? Get it listed too →