Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
brutas — Wordlists handcrafted (and automated) with ♥ | Kitploit
Tools/GitHubGitHub/tasooshi/brutas
Password CrackingReconnaissancePassword AttacksInformation GatheringPenetration Testing
GitHubtasooshi/brutas

brutas

Wordlists handcrafted (and automated) with ♥

View Repository
23527711 year agoReviewed by Kitploit

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

brutas

Wordlists handcrafted (and automated) with ♥

A random passwords sample:

1qaz2wsx            | panel197111         | @bcd1234            | Root!22020
1q2w3e4r5t6y        | catalog841@@        | Zaq@#$m,.           | 1Qazxsw@222
qwerty12345         | Asdzxc129191        | testguest           | User@#$12@
password123         | qwerty!@12345       | Guest1120           | ?99998888?
123321!             | Cloud03%%           | rootj               | administrator8,4
p$ssw0rd            | abcdefghi27         | administrator/test  | test3#@121
qweqweqwe           | !1q2w3e4rt|59       | .321Root            | (ASDQWE1)
admin!              | *12shellshell12#$   | root,32020          | Qwas07
pass!               | 00!integration      | Viper               | guest3422!
98989898            | zimbra@273          | Midnight1           | zxccvbnm321

Requirements:

  • Python 3.9, 3.10
  • hashcat
  • hashcat-utils
  • GNU tools: cat, awk, comm, sort, uniq
  • wordz (pypi)

Recommended:

  • lzop
  • hashcat compiled from the master branch

Usage

Precompiled

The precompiled lists are located at:

brutas/wordlists/dns
brutas/wordlists/http
brutas/wordlists/passwords
brutas/wordlists/ports
brutas/wordlists/usernames

NOTE: Due to Github limits only the "reasonably" sized lists are precompiled. You need to run the build scripts yourself to generate the complete set (compile.sh and huge.sh).

The lists which are not included in this repository are hosted here and get updated occassionally:

  • brutas-passwords-5-l.zip [updated 2025/08/01] (71,621,639 lines - 722MB decompressed)
  • brutas-passwords-6-xl.zip [updated 2025/08/01] (347,450,342 - 4.1GB decompressed)

These ones you will have to compile yourself:

  • brutas-passwords-7-xxl (18,008,399,243 lines - 237GB decompressed)
  • brutas-http-paths-all.zip (261,481,011 lines - 5.3GB decompressed)

Keyword sources

Source files for keywords are located in src/keywords. You may find them interesting, especially when building language-specific dictionaries.

Save bandwidth

If you want to get the latest files only ("a shallow clone with a history truncated to the specified number of commits"):

% git clone --depth 1 https://github.com/tasooshi/brutas.git

Building

You need to install wordz (the wordlist automation framework) first:

% pip install wordz

The build process is automated and handled by the scripts located in the root of the project. You may want to keep the temporary files, sometimes they work pretty well on their own, so you don't have to launch the full attack. The following will produce 1-6-*.txt passwords, as well as subdomains and basic HTTP lists:

~/brutas:% ./compile.sh

For the rest (7-xxl.txt and all HTTP paths) run:

~/brutas:% ./huge.sh -t /media/user/ExternalDrive/tmp

Custom wordlists

All batteries-included

If you want to generate a custom wordlist (wordlists/passwords/custom.txt) based on keywords in src/keywords/custom.txt, use the following:

~/brutas:% ./custom.sh -t /media/user/ExternalDrive/tmp -o /media/users/AnotherDrive/new

Be aware that building a custom list requires a lot of resources. If you'd like to see what kind of results you may expect, check out the example wordlists/passwords/custom.txt based on a single word love (generates over 150MB of data and 12,591,796 uniques currently, trimmed to randomly selected 10k lines). A tiny sample below:

---LoveLove1!1                  | 2022_|ove!23
love!5`80                       | love!5|79
55!lov607                       | 10v34444@#
Love'10#61                      | 22`Lovelove))
Loveo2020@                      | Love&01,78
love$1$64                       | ()LoveLove+^+
love9/79                        | 2021$lov3111+++
l0ve123212                      | Love+91979
|ove66612345!                   | Loveasd,.
Love^0259                       | l)v#22$#@!
Optimized for specific targets

You can also generate a custom wordlist optimized for the name of the targeted organization (put the name in src/keywords/custom.txt), using the following class:

~/brutas:% wordz -p src/classes/passwords.py::OrganizationNamePasswords

There's also another version of the class that works well for product names, brands etc:

~/brutas:% wordz -p src/classes/passwords.py::OrganizationKeywordsPasswords

Using specific language

There are two options:

  1. either overwrite lang-int-*.txt files;
  2. or use the CustomPasswords class with keywords copied to src/keywords/custom.txt.

The first one would cause the build to use the specific language as the base, while other languages would still be used (starting with wordlists/passwords/6-xl.txt list). The second option would ignore the normal build process and use the full set of rules on the src/keywords/custom.txt file. You should expect a massive output in that case.

Common problems

Kali Linux hashcat-utils

The hashcat utilities are located at /usr/lib/hashcat-utils/, you need to add this $PATH to your .zshrc.

Missing OpenCL / non-GPU setup

In case you are not going to use GPUs (No OpenCL, HIP or CUDA compatible platform found), you may find this one helpful:

# apt install pocl-opencl-icd

Introduction

Why these password lists are different? The goal here is not to crack every password possible, it is to move forward inside a network. And if cracking is really needed then the bigger lists can be used. However, the assumption here is that it will be done in a reasonable time span and with limited resources (like a VM, hijacked host etc).

A brief introduction to password lists:

  • the number of passwords grows with the consecutive file number;
  • passwords are not sorted according to the probability, they are combined into groups of probability instead;
  • each consecutive file does not contain passwords from any of the previous sets.

wordlists/passwords

  • {1-7}-*.txt - passwords generated using international keywords, hashcat rules and string partials
  • classics.txt - typical admin passwords based on roles (test, admin), words (password, secret) or "funny" ones (like letmein or trustno1), no patterns
  • patterns.txt - close key combinations or simple phrases (e.g. abcd) combined with capitalization, numbers, repetitions etc.
  • top.txt - is a list composed of most popular user passwords found in leaks, doesn't contain close keys or any more sophisticated combinations
  • generic-1k.txt - 1-xxs.txt plus manually selected passwords from the other sets
  • unique.txt - passwords which are complex enough to be used as independent passwords and are rarely mixed with any extra characters, usually related to pop-culture or sports (e.g. apollo13, 9inchnails, ronaldo7)
  • numbers.txt - a small list of numbers used in passwords (e.g. dates, math constants)
  • custom.txt - put your custom keywords here and generate the wordlist using custom.sh or custom-mini.sh, the result will be in wordlists/passwords/custom{-mini}.txt

Other lists

Download Tool