{ "usernames": { "prefixes": [ "admin", "user", "developer", "root", "system", "db", "api", "service", "deploy", "test", "prod", "backup", "monitor", "jenkins", "webapp" ], "suffixes": [ "", "_prod", "_dev", "_test", "123", "2024", "_backup", "_admin", "01", "02", "_user", "_service", "_api" ] }, "passwords": { "prefixes": [ "P@ssw0rd", "Passw0rd", "Admin", "Secret", "Welcome", "System", "Database", "Secure", "Master", "Root" ], "simple": [ "test", "demo", "temp", "change", "password", "admin", "letmein", "welcome", "default", "sample" ] }, "emails": { "domains": [ "example.com", "company.com", "localhost.com", "test.com", "domain.com", "corporate.com", "internal.net", "enterprise.com", "business.org" ] }, "api_keys": { "prefixes": [ "sk_live_", "sk_test_", "api_", "key_", "token_", "access_", "secret_", "prod_", "" ] }, "databases": { "names": [ "production", "prod_db", "main_db", "app_database", "users_db", "customer_data", "analytics", "staging_db", "dev_database", "wordpress", "ecommerce", "crm_db", "inventory" ], "hosts": [ "localhost", "db.internal", "mysql.local", "postgres.internal", "127.0.0.1", "db-server-01", "database.prod", "sql.company.com" ] }, "applications": { "names": [ "WebApp", "API Gateway", "Dashboard", "Admin Panel", "CMS", "Portal", "Manager", "Console", "Control Panel", "Backend" ] }, "users": { "roles": [ "Administrator", "Developer", "Manager", "User", "Guest", "Moderator", "Editor", "Viewer", "Analyst", "Support" ] }, "directory_listing": { "files": [ "test.exe", "backup.sql", "database.sql", "db_backup.sql", "dump.sql", "config.php", "credentials.txt", "passwords.txt", "users.csv", ".env", "id_rsa", "id_rsa.pub", "private_key.pem", "api_keys.json", "secrets.yaml", "admin_notes.txt", "settings.ini", "database.yml", "wp-config.php", ".htaccess", "server.key", "cert.pem", "shadow.bak", "passwd.old" ], "directories": [ "uploads/", "backups/", "logs/", "temp/", "cache/", "private/", "config/", "admin/", "database/", "backup/", "old/", "archive/", ".git/", "keys/", "credentials/" ] }, "error_codes": [ 400, 401, 403, 404, 500, 502, 503 ], "server_headers": [ "Apache/2.4.41 (Ubuntu)", "nginx/1.18.0", "Microsoft-IIS/10.0", "cloudflare", "AmazonS3", "gunicorn/20.1.0" ], "attack_urls": { "path_traversal": "\\.\\.", "sql_injection": "('|--|;|\bOR\b|\bUNION\b|\bSELECT\b|\bDROP\b)", "xss_attempt": "(