← All repos

SecLists

SecLists is the security tester's companion. It's a collection of multiple types of lists used during security assessments, collected in one place. List types include usernames, passwords, URLs, sensitive data patterns, fuzzing payloads, web shells, and many more.

Browse cluster: Claude AI Agent Frameworks & MCP Tools
6,734commits
381contributors
13languages

Tech stack & purpose

SecLists is a comprehensive collection of multiple types of lists used during security assessments, including usernames, passwords, URLs, sensitive data patterns, fuzzing payloads, and web shells. The repository contains specialized datasets for testing language models' safety boundaries—such as jailbreak prompts collected from platforms like Reddit and a forbidden question set covering 13 ethical scenarios derived from OpenAI's usage policies—as well as wordlists for discovering DNS subdomains, fuzzing web application APIs, and testing legacy systems like CGI scripts and Content Management Systems. The LLM testing materials, particularly those in the Ethical and Safety Boundaries directory, originate from research by Xinyue Shen, Zeyuan Chen, Michael Baces, Yun Shen, and Yang Zhang for an ACM CCS 2024 paper on jailbreak prompts.

Community & reference links

Languages

PHP
52.0%
Python
16.5%
Classic ASP
11.5%
Shell
7.4%
Perl
3.8%
Java
2.8%
ASP.NET
2.5%
ColdFusion
1.9%
HTML
1.1%
C
0.5%
Awk
0.1%
Makefile
0.1%
Hack
0.0%

Contributors (top 30 of 381)