Skip to content
CatSuite

Language

Choose whether the site follows your browser or always uses Brazilian Portuguese or English.

Get it free

Modules

Wordlists and payloads

Wordlists and payloads in CatSuite: how to import .txt lists, use default wordlists, configure the payload generator and apply them in Intruder and Discovery.

11 min read

Wordlists and payloads in CatSuite gather the word lists that feed the app's local attacks: the built-in default wordlists, the user-added wordlists (imported as .txt) and the payload generators that build numeric sequences on the fly. This module explains what a wordlist is, how to import and validate a file, how the Intruder's payload generator works and how to select each list in the Intruder and the Discoverer.

What wordlists and payloads are in CatSuite #

A wordlist is a text file with one entry per line. Each line becomes a value that CatSuite injects into a position on the target during an authorized test. A payload is each concrete value that comes out of a wordlist (or a generator) and enters the request. The wordlist module is the central place where these lists are organized, imported, validated and stored for reuse by the attack modules.

CatSuite separates lists by origin: the default wordlists, which ship inside the app and cannot be deleted, and the user wordlists, which you import from a .txt file. Beyond the ready-made lists, the Intruder offers the dynamic generator, which produces a sequence of numeric payloads from a few parameters, with no file needed.

Core concepts #

Wordlist and the .txt format #

An imported wordlist is always a plain-text .txt file, with one entry per line. The CatSuite file picker accepts only the .txt extension (types text/plain and application/octet-stream). Empty lines and content with no usable value are discarded during validation; if the file has no usable line, the import is rejected.

example-directories.txtText
admin
login
api
api/v1
api/v2
backup
config
uploads
.git

Default wordlists versus user-added wordlists #

The default wordlists (label APP DEFAULT) are protected: they ship inside the app, appear at the top of the catalog and cannot be renamed or deleted. The user wordlists (label ADDED BY USER) are the ones you import; they appear right below the internal lists and can be renamed and removed at any time.

Payload and payload generator #

A payload is each value sent to the target. It can come from a wordlist (one payload per line) or from a dynamic generator, which builds a sequence of numbers from a start, an end and a step, with the option to pad with leading zeros and add a prefix and a suffix. The generator is handy when you need to test ranges such as 1 to 1000 or identifiers shaped like user0001, user0002 without keeping a huge file.

Protected reading and safe mode #

For large files, CatSuite enables protected reading (also shown as SAFE MODE): the wordlist is streamed line by line instead of loading everything into device memory at once. This helps prevent slowdowns when the list runs. The line count is computed and saved during validation, so the catalog shows the total even without reopening the file.

The $CAT$ marker #

In the attack modules, the exact point where each wordlist word enters the request is marked with $CAT$. In the Discoverer the marker goes in the base URL; in the Intruder it marks the positions inside the request. Without the marker, the app does not know where to apply the payload.

The wordlist screen #

The wordlist screen (under Settings > Wordlist) manages the default lists, the custom lists, the import and the validation. It is split into two sections and shows, for each item, the origin, count and size labels.

Standard wordlists section #

The STANDARD WORDLISTS section lists the bases that ship with the app. Each item shows the name, the usage description, the line count and the APP DEFAULT label. These items are protected and offer no rename or delete action.

User wordlists section #

The USER WORDLISTS section gathers the lists you have imported. Each item carries the editable name, the WORDLIST ARCHIVE field (the associated .txt file), the line count, the size and the ADDED BY USER label. This is where the rename and delete actions live. When no list has been imported, the section stays empty until you use ADD WORDLIST.

Labels on each item #

Each catalog item shows labels computed from the file:

LabelWhat it shows
APP DEFAULT / ADDED BY USERThe wordlist origin (default or user).
Line countThe total number of entries, or On demand when the count was not fixed.
SizeThe file size in B, KB or MB; Internal for default lists.
PROTECTED READING / SAFE MODEShown when the list is large and will be streamed.

Included default wordlists #

CatSuite already ships two ready-made bases, aimed at the two attack modules:

NameRecommended useLinesOrigin
CatSuite Directories and APIEnumerating paths and endpoints in the Discoverer module.4,750APP DEFAULT
CatSuite ParametersParameter and variation testing in the Intruder module.6,453APP DEFAULT

Both lists are stored internally in a compressed format and handled in safe reading mode, which is why they show the size Internal.

How to add a wordlist (import .txt) #

The ADD WORDLIST button opens the flow to import a custom list in .txt. The file is selected, validated, counted and copied in the background into the app.

Step by step #

  1. Open Settings > Wordlist.
  2. Tap ADD WORDLIST.
  3. Choose a .txt file in the device picker.
  4. Wait for validation (VALIDATING WORDLIST): CatSuite checks the format and counts the lines.
  5. Confirm. If the file is large, the app warns that it will use protected reading.
  6. The message Wordlist added successfully confirms it is now in the catalog.
  7. Optional: rename the list to a short, clear name (up to 48 characters).

What happens during validation #

During validation, CatSuite checks whether the file is a compatible .txt and counts the usable lines to save that total in the catalog. It then makes a protected copy of the content in the app's private directory. If the file fails the format check, or has no usable content, the import is rejected with an explanatory message.

Protected reading for large files #

When the file is large, CatSuite marks the wordlist for protected reading and reports that it will handle it in safe mode because of its size. In operation, the list is streamed line by line, even with very large files, which avoids loading everything into device memory.

Wordlist item options and how to configure them #

Each catalog wordlist is described by a set of fields. Some you adjust (such as the name), others are filled in by the import or by the internal list.

OptionValuesDefaultWhat it does
NameText up to 48 charactersFile nameLabel shown in the catalog and in the module selectors.
Wordlist archive.txt fileThe imported oneThe file tied to the list; shown in the WORDLIST ARCHIVE field.
Format.txt (user) / .gz (default).txtContent extension; default lists are internal and compressed.
OriginDefault / CustomCustomSets whether the list is protected (default) or editable (user).
Line countNumber or On demandFrom validationTotal entries saved on import.
Protected readingOn / OffAutomaticTurned on for large files, forcing streamed reading.

The only field you edit freely is the name: it is capped at 48 characters and, if you leave it blank, it falls back to a default value. The remaining fields reflect the imported file and need no manual adjustment.

Buttons and actions #

Button / actionWhat it does
ADD WORDLISTOpens the .txt file picker and starts the import and validation.
RENAME WORDLISTChanges the name of a user list (up to 48 characters).
Delete wordlistRemoves a user list from the catalog and the app.

The Intruder payload generator #

In the Intruder, the ORIGIN OF PAYLOADS area lets you choose between using Wordlists or Dynamic Generators. The DYNAMIC GENERATOR creates a sequence of numeric payloads from a few parameters, with no file needed. Each payload has the shape prefix + number + suffix, and the number can be padded with leading zeros.

Generator options and how to configure them #

OptionValuesDefaultWhat it does
StartInteger1First number in the sequence.
EndInteger25Last number in the sequence.
StepInteger greater than 01Increment from one number to the next.
PaddingInteger0Number width with leading zeros; 0 means no padding.
PrefixTextemptyFixed text before the number.
SuffixTextemptyFixed text after the number.

Start with Start and End to set the range. Use Step to skip values (for example, in tens). Padding guarantees a fixed width, useful for identifiers with leading zeros. Prefix and Suffix wrap the number with fixed text, such as user or .php.

Payload estimate #

The screen shows the Current estimate of payloads as you adjust the fields. The total is computed as ((end - start) / step) + 1. If Step is zero or negative, or if End is smaller than Start, the estimate is zero and no payload is produced.

Output examples #

Simple sequence from 1 to 5, with no padding:

Start 1, End 5, Step 1Text
1
2
3
4
5

Identifiers with a prefix and 4-digit padding:

Start 1, End 5, Padding 4, Prefix userText
user0001
user0002
user0003
user0004
user0005

Range from 0 to 100 with a step of 10:

Start 0, End 100, Step 10Text
0
10
20
30
40
50
60
70
80
90
100

How to select the wordlist in each module #

In the Discoverer #

In the Discoverer, the DISCOVERER WORDLIST section lets you select the list the module will run through. Use the internal lists or the wordlists you added; the selector is refreshed when opened and shows the internal lists at the top. The point where each word enters the URL is marked with $CAT$.

Base URL in the DiscovererText
https://target.com/api/$CAT$

If the configured wordlist is unavailable, the Discoverer asks you to open the settings and select another one.

In the Intruder #

In the Intruder, you choose the ORIGIN OF PAYLOADS between Wordlists and Dynamic Generators. When using a wordlist, the INTRUDER WORDLIST section lists the same default and custom bases from the catalog. The positions to test are marked with $CAT$ inside the request. You must select a wordlist (or configure the generator) before starting the intrusion.

Limits and best practices #

  • Name: up to 48 characters per wordlist.
  • Import format: only plain-text .txt, one entry per line.
  • Large files: automatically enter protected reading (safe mode) and are streamed.
  • Storage: imported lists are copied into the app's private directory; the original file does not need to stay on the device.
  • Generator: step must be greater than zero and end must not be smaller than start, or the estimate stays at zero.

Common problems / FAQ #

Does the picker only accept .txt? Yes. The import validates the extension and the content; files in other formats are rejected.

Why does my list show "On demand"? When the line count was not fixed, the catalog shows On demand instead of the number. Reimport the file to save the count.

Can I delete the default wordlists? No. Lists labeled APP DEFAULT are protected and offer no rename or delete.

The wordlist disappeared when I started the attack. If the configured list is unavailable, the module asks you to open the settings and select another one, or reimport the file. In the Intruder, select a wordlist before starting the intrusion.

The generator produced no payloads. Check that the step is greater than zero and that the end is greater than or equal to the start; the estimate must be greater than zero.

Where are the imported lists stored? In a protected copy inside the app's private directory. Clearing the app data removes the custom wordlists along with settings, sessions and history.

Next step #