# Wordlists and payloads

> Wordlists and payloads in CatSuite: how to import .txt lists, use default wordlists, configure the payload generator and apply them in Intruder and Discovery.

- Language: en
- Canonical URL: https://netcattest.com/catsuite/en/docs/modules/wordlists
- Section: Modules
- Updated: 2026-10-06
- Other language (pt-BR): https://netcattest.com/catsuite/docs/modulos/wordlists

**Wordlists and payloads** in CatSuite gather the word lists that feed the app's local attacks: the built-in **default wordlists**, the **user-added wordlists** (imported as `.txt`) and the **payload generators** that build numeric sequences on the fly. This module explains what a wordlist is, how to import and validate a file, how the Intruder's payload generator works and how to select each list in the [Intruder](https://netcattest.com/catsuite/en/docs/modules/intruder) and the [Discoverer](https://netcattest.com/catsuite/en/docs/modules/discoverer).

## What wordlists and payloads are in CatSuite

A **wordlist** is a text file with one entry per line. Each line becomes a value that CatSuite injects into a position on the target during an authorized test. A **payload** is each concrete value that comes out of a wordlist (or a generator) and enters the request. The wordlist module is the central place where these lists are organized, imported, validated and stored for reuse by the attack modules.

CatSuite separates lists by origin: the **default wordlists**, which ship inside the app and cannot be deleted, and the **user wordlists**, which you import from a `.txt` file. Beyond the ready-made lists, the Intruder offers the **dynamic generator**, which produces a sequence of numeric payloads from a few parameters, with no file needed.

> [!NOTE]
> The wordlist screen lives under **Settings > Wordlist**. From there you manage the default and custom lists, import new files and follow the validation of each one.

## Core concepts

### Wordlist and the .txt format

An imported wordlist is always a plain-text `.txt` file, with one entry per line. The CatSuite file picker accepts only the `.txt` extension (types `text/plain` and `application/octet-stream`). Empty lines and content with no usable value are discarded during validation; if the file has no usable line, the import is rejected.

```text
admin
login
api
api/v1
api/v2
backup
config
uploads
.git
```

### Default wordlists versus user-added wordlists

The **default wordlists** (label **APP DEFAULT**) are protected: they ship inside the app, appear at the top of the catalog and cannot be renamed or deleted. The **user wordlists** (label **ADDED BY USER**) are the ones you import; they appear right below the internal lists and can be renamed and removed at any time.

> [!TIP]
> In the module wordlist selector, the internal lists appear first and your imported lists appear below them. The selector is refreshed every time you open it, so a freshly imported list is immediately available.

### Payload and payload generator

A **payload** is each value sent to the target. It can come from a wordlist (one payload per line) or from a **dynamic generator**, which builds a sequence of numbers from a start, an end and a step, with the option to pad with leading zeros and add a prefix and a suffix. The generator is handy when you need to test ranges such as `1` to `1000` or identifiers shaped like `user0001`, `user0002` without keeping a huge file.

### Protected reading and safe mode

For large files, CatSuite enables **protected reading** (also shown as **SAFE MODE**): the wordlist is streamed line by line instead of loading everything into device memory at once. This helps prevent slowdowns when the list runs. The line count is computed and saved during validation, so the catalog shows the total even without reopening the file.

> [!IMPORTANT]
> On import, CatSuite makes a **protected copy** of the file inside the app's private directory. The list keeps working even if the original file is moved or deleted later.

### The $CAT$ marker

In the attack modules, the exact point where each wordlist word enters the request is marked with `$CAT$`. In the Discoverer the marker goes in the base URL; in the Intruder it marks the positions inside the request. Without the marker, the app does not know where to apply the payload.

## The wordlist screen

The wordlist screen (under **Settings > Wordlist**) manages the default lists, the custom lists, the import and the validation. It is split into two sections and shows, for each item, the origin, count and size labels.

### Standard wordlists section

The **STANDARD WORDLISTS** section lists the bases that ship with the app. Each item shows the name, the usage description, the line count and the **APP DEFAULT** label. These items are protected and offer no rename or delete action.

### User wordlists section

The **USER WORDLISTS** section gathers the lists you have imported. Each item carries the editable name, the **WORDLIST ARCHIVE** field (the associated `.txt` file), the line count, the size and the **ADDED BY USER** label. This is where the rename and delete actions live. When no list has been imported, the section stays empty until you use **ADD WORDLIST**.

### Labels on each item

Each catalog item shows labels computed from the file:

| Label | What it shows |
| --- | --- |
| APP DEFAULT / ADDED BY USER | The wordlist origin (default or user). |
| Line count | The total number of entries, or **On demand** when the count was not fixed. |
| Size | The file size in B, KB or MB; **Internal** for default lists. |
| PROTECTED READING / SAFE MODE | Shown when the list is large and will be streamed. |

## Included default wordlists

CatSuite already ships two ready-made bases, aimed at the two attack modules:

| Name | Recommended use | Lines | Origin |
| --- | --- | --- | --- |
| CatSuite Directories and API | Enumerating paths and endpoints in the Discoverer module. | 4,750 | APP DEFAULT |
| CatSuite Parameters | Parameter and variation testing in the Intruder module. | 6,453 | APP DEFAULT |

Both lists are stored internally in a compressed format and handled in safe reading mode, which is why they show the size **Internal**.

> [!TIP]
> Start with the default lists before importing your own. The **CatSuite Directories and API** base is the natural choice for the Discoverer, and **CatSuite Parameters** was prepared for the Intruder.

## How to add a wordlist (import .txt)

The **ADD WORDLIST** button opens the flow to import a custom list in `.txt`. The file is selected, validated, counted and copied in the background into the app.

### Step by step

1. Open **Settings > Wordlist**.
2. Tap **ADD WORDLIST**.
3. Choose a `.txt` file in the device picker.
4. Wait for validation (**VALIDATING WORDLIST**): CatSuite checks the format and counts the lines.
5. Confirm. If the file is large, the app warns that it will use **protected reading**.
6. The message **Wordlist added successfully** confirms it is now in the catalog.
7. Optional: rename the list to a short, clear name (up to 48 characters).

### What happens during validation

During validation, CatSuite checks whether the file is a compatible `.txt` and counts the usable lines to save that total in the catalog. It then makes a protected copy of the content in the app's private directory. If the file fails the format check, or has no usable content, the import is rejected with an explanatory message.

### Protected reading for large files

When the file is large, CatSuite marks the wordlist for **protected reading** and reports that it will handle it in **safe mode** because of its size. In operation, the list is streamed line by line, even with very large files, which avoids loading everything into device memory.

> [!WARNING]
> Import only files you trust. The wordlist feeds real requests in the attack modules; use it only against authorized targets.

## Wordlist item options and how to configure them

Each catalog wordlist is described by a set of fields. Some you adjust (such as the name), others are filled in by the import or by the internal list.

| Option | Values | Default | What it does |
| --- | --- | --- | --- |
| Name | Text up to 48 characters | File name | Label shown in the catalog and in the module selectors. |
| Wordlist archive | `.txt` file | The imported one | The file tied to the list; shown in the **WORDLIST ARCHIVE** field. |
| Format | `.txt` (user) / `.gz` (default) | `.txt` | Content extension; default lists are internal and compressed. |
| Origin | Default / Custom | Custom | Sets whether the list is protected (default) or editable (user). |
| Line count | Number or On demand | From validation | Total entries saved on import. |
| Protected reading | On / Off | Automatic | Turned on for large files, forcing streamed reading. |

The only field you edit freely is the **name**: it is capped at 48 characters and, if you leave it blank, it falls back to a default value. The remaining fields reflect the imported file and need no manual adjustment.

## Buttons and actions

| Button / action | What it does |
| --- | --- |
| ADD WORDLIST | Opens the `.txt` file picker and starts the import and validation. |
| RENAME WORDLIST | Changes the name of a user list (up to 48 characters). |
| Delete wordlist | Removes a user list from the catalog and the app. |

> [!DANGER]
> Deleting a user wordlist is final inside the app: the protected copy is removed. Keep the original `.txt` file outside CatSuite if you want to reimport it later.

## The Intruder payload generator

In the Intruder, the **ORIGIN OF PAYLOADS** area lets you choose between using **Wordlists** or **Dynamic Generators**. The **DYNAMIC GENERATOR** creates a sequence of numeric payloads from a few parameters, with no file needed. Each payload has the shape prefix + number + suffix, and the number can be padded with leading zeros.

### Generator options and how to configure them

| Option | Values | Default | What it does |
| --- | --- | --- | --- |
| Start | Integer | 1 | First number in the sequence. |
| End | Integer | 25 | Last number in the sequence. |
| Step | Integer greater than 0 | 1 | Increment from one number to the next. |
| Padding | Integer | 0 | Number width with leading zeros; 0 means no padding. |
| Prefix | Text | empty | Fixed text before the number. |
| Suffix | Text | empty | Fixed text after the number. |

Start with **Start** and **End** to set the range. Use **Step** to skip values (for example, in tens). **Padding** guarantees a fixed width, useful for identifiers with leading zeros. **Prefix** and **Suffix** wrap the number with fixed text, such as `user` or `.php`.

### Payload estimate

The screen shows the **Current estimate** of payloads as you adjust the fields. The total is computed as `((end - start) / step) + 1`. If **Step** is zero or negative, or if **End** is smaller than **Start**, the estimate is zero and no payload is produced.

### Output examples

Simple sequence from `1` to `5`, with no padding:

```text
1
2
3
4
5
```

Identifiers with a prefix and 4-digit padding:

```text
user0001
user0002
user0003
user0004
user0005
```

Range from `0` to `100` with a step of `10`:

```text
0
10
20
30
40
50
60
70
80
90
100
```

> [!NOTE]
> If the generator produces no payloads, or the selected wordlist returns no usable values, the Intruder warns you before starting. Review the range, the step and the list selection.

## How to select the wordlist in each module

### In the Discoverer

In the [Discoverer](https://netcattest.com/catsuite/en/docs/modules/discoverer), the **DISCOVERER WORDLIST** section lets you select the list the module will run through. Use the internal lists or the wordlists you added; the selector is refreshed when opened and shows the internal lists at the top. The point where each word enters the URL is marked with `$CAT$`.

```text
https://target.com/api/$CAT$
```

If the configured wordlist is unavailable, the Discoverer asks you to open the settings and select another one.

### In the Intruder

In the [Intruder](https://netcattest.com/catsuite/en/docs/modules/intruder), you choose the **ORIGIN OF PAYLOADS** between **Wordlists** and **Dynamic Generators**. When using a wordlist, the **INTRUDER WORDLIST** section lists the same default and custom bases from the catalog. The positions to test are marked with `$CAT$` inside the request. You must select a wordlist (or configure the generator) before starting the intrusion.

## Limits and best practices

- **Name:** up to 48 characters per wordlist.
- **Import format:** only plain-text `.txt`, one entry per line.
- **Large files:** automatically enter protected reading (safe mode) and are streamed.
- **Storage:** imported lists are copied into the app's private directory; the original file does not need to stay on the device.
- **Generator:** step must be greater than zero and end must not be smaller than start, or the estimate stays at zero.

> [!TIP]
> Give your lists short, descriptive names (for example, `api-v1-routes` or `params-login`). Clear names make selection easier in the Intruder and Discoverer selectors.

## Common problems / FAQ

**Does the picker only accept `.txt`?** Yes. The import validates the extension and the content; files in other formats are rejected.

**Why does my list show "On demand"?** When the line count was not fixed, the catalog shows **On demand** instead of the number. Reimport the file to save the count.

**Can I delete the default wordlists?** No. Lists labeled **APP DEFAULT** are protected and offer no rename or delete.

**The wordlist disappeared when I started the attack.** If the configured list is unavailable, the module asks you to open the settings and select another one, or reimport the file. In the Intruder, select a wordlist before starting the intrusion.

**The generator produced no payloads.** Check that the step is greater than zero and that the end is greater than or equal to the start; the estimate must be greater than zero.

**Where are the imported lists stored?** In a protected copy inside the app's private directory. Clearing the app data removes the custom wordlists along with settings, sessions and history.

## Next step

- [Intruder](https://netcattest.com/catsuite/en/docs/modules/intruder)
- [Discoverer](https://netcattest.com/catsuite/en/docs/modules/discoverer)
- [Repeater](https://netcattest.com/catsuite/en/docs/modules/repeater)
- [Modules overview](https://netcattest.com/catsuite/en/docs/modules)
- [Safe and responsible use](https://netcattest.com/catsuite/en/docs/security)
