+1 rockyou.txt  Hashcat with rules, and a script that stuffs found PW's back into rockyou.txt

If you are doing hashcat, learn rules, combiner, and hybrid attacks.  Know your target.  Straight up dictionary is almost pointless (though local area code phone numbers and rockyou.txt get a *lot* of WiFi PWs in these parts)


Crackstaion.txt is all but useless (for a multi GB file), but have gotten a  few positives from it.  If you look at it, it has a TON of crap.  Like full windows path/filenames.  Its a bloody mess of junk.

Some of these are pre-installed in kali, others not for size but have at it:




There are quire a few places like this for wordlists, just have to google for them. I've been using the above link for working on Vulnhub CTF's and have had decent success with them. You can also try tools like digininjas cewl and rsmangler combined with john the ripper to make wordlists for you. crunch is also a nice tool for making number and letter sets based on rules, but warning, files can get large quick if you don't pay attention to the rules and length, you will fill a HDD very quickly if not careful.

