Provides curated lists of common usernames and default credentials for authorized security testing and penetration tests on your infrastructure.
Best for: Security teams running authorized audits against their own systems.
---
name: security-usernames
description: "Top username lists for enumeration: common usernames, default credentials, names. Curated essentials for authorized testing."
---
# SecLists Usernames (Curated)
## Description
Top username lists for enumeration: common usernames, default credentials, names. Curated essentials for authorized testing.
**Source:** [SecLists/Usernames](https://github.com/danielmiessler/SecLists/tree/master/Usernames)
**Repository:** https://github.com/danielmiessler/SecLists
**License:** MIT
## When to Use This Skill
Use this skill when you need:
- Username enumeration (authorized)
- Default credential testing
- User discovery
- Account validation
**⚠️ IMPORTANT:** Only use for authorized security testing, bug bounty programs, CTF competitions, or educational purposes.
## Key Files in This Skill
- `top-usernames-shortlist.txt - Most common usernames`
- `cirt-default-usernames.txt - Default system usernames`
- `Names/names.txt - Common first/last names`
## Usage Example
```python
# Access files from this skill
import os
# Example: Load patterns/payloads
skill_path = "references/Usernames"
# List all available files
for root, dirs, files in os.walk(skill_path):
for file in files:
if file.endswith('.txt'):
filepath = os.path.join(root, file)
print(f"Found: {filepath}")
# Read file content
with open(filepath, 'r', errors='ignore') as f:
content = f.read().splitlines()
print(f" Lines: {len(content)}")
```
## Security & Ethics
### Authorized Use Cases ✅
- Authorized penetration testing with written permission
- Bug bounty programs (within scope)
- CTF competitions
- Security research in controlled environments
- Testing your own systems
- Educational demonstrations
### Prohibited Use Cases ❌
- Unauthorized access attempts
- Testing without permission
- Malicious activities
- Privacy violations
- Any illegal activities
## Complete SecLists Collection
This is a curated subset of SecLists. For the complete collection:
- **Full repository:** https://github.com/danielmiessler/SecLists
- **Size:** 4.5 GB with 6,000+ files
- **All categories:** Passwords, Usernames, Discovery, Fuzzing, Payloads, Web-Shells, Pattern-Matching, AI, Miscellaneous
---
**Generated by Skill Seeker** | SecLists Usernames Collection
**License:** MIT - Use responsibly with proper authorization
Creator's repository · eyadkelleh/awesome-skills-security