Open-source project
ihebski/DefaultCreds-cheat-sheet avatar
ihebski/DefaultCreds-cheat-sheet

DefaultCreds-cheat-sheet: a searchable database of default logins for pentests and blue-team audits

One place for all the default credentials to assist the Blue/Red teamers identifying devices with default password 🛡️

6,766 stars788 forksPythonMIT

At a glance

What is it?
The project ships a CSV of 3711 default credential rows and a small Python CLI called creds that searches it, updates it, and exports username and password lists. It is a dataset with a lookup tool, not a scanner.
Who is it for?
Adopt it if you are a pentester or blue teamer who needs a fast, offline lookup of vendor default logins and a way to export username and password lists for an authorised test. Do not adopt it if you expect it to discover devices, attempt logins or scan a network on its own; it is a dataset with a search command.
Can I use it commercially?
Yes. MIT is a permissive licence: you can use, modify and sell software built on it, as long as you keep its copyright and licence notices.
Is it still maintained?
Yes. The repository last received commits 4 days ago.
What is it written in?
Mainly Python, according to GitHub's language statistics.

Answers come from the project's GitHub data, last synced on October 1, 2026, and from our analysis. They are not legal advice.

Editorial analysis

What the default credentials cheat sheet actually is

The repository is a CSV file and a command-line wrapper around it. DefaultCreds-Cheat-Sheet.csv holds 3711 rows, each with a product or vendor, a username and a password. The README's own stats table counts 1398 unique products, 1121 unique usernames and 1680 unique passwords, with Oracle the most frequent product at 235 rows and blank values the most common username and password. Those blanks matter: many appliances ship with no password set at all, so an empty field is a finding, not missing data.

The audience is stated plainly. Pentesters use it during an engagement to try known vendor logins against a device they are authorised to test. Blue teamers use it the other way round, to check whether anything in their estate still answers to a factory login. The README points to the OWASP Web Security Testing Guide, test WSTG-ATHN-02, Testing for Default Credentials, as the methodology this data supports. The CSV is the artefact; creds is the convenience layer.

Where the 3711 rows come from and what that means for coverage

The README lists the sources: changeme, routersploit, betterdefaultpasslist, Seclists' Default-Credentials wordlist, ics-default-passwords, and vendor documentation or blogs. That provenance explains the shape of the data. changeme and routersploit are scanner projects with their own device fingerprints, so the rows inherited from them skew toward network gear, printers and IoT. Seclists contributes broad application coverage. The ICS list adds industrial control equipment that a general wordlist would miss.

Aggregation also means the dataset inherits the gaps of its sources. A vendor that none of those projects documented will not appear unless someone submitted a pull request, and the README's contribution section is exactly that: open a PR to update the dataset. There is no vendor-maintained feed and no verification step described in the repository. Treat a missing product as unknown rather than as proof that no default exists.

Installing creds from PyPI and running a first search

The README gives a two-command install from PyPI. The package name on PyPI is defaultcreds-cheat-sheet while setup.py declares the distribution name default-creds and version 0.5.3, so do not be surprised if pip output differs from the command you typed. The entry point is a script named creds.

bash
pip3 install defaultcreds-cheat-sheet
creds search tomcat

You should see a prettytable with three columns, Product, username and password, listing rows such as apache tomcat (web) with tomcat/tomcat and admin/admin. The README marks Linux (Kali, Ubuntu, Lubuntu), Windows 10 and 11, and macOS as tested.

If you prefer to run from a clone, the manual path copies the script onto your PATH:

bash
git clone https://github.com/ihebski/DefaultCreds-cheat-sheet
pip3 install -r requirements.txt
cp creds /usr/bin/ && chmod +x /usr/bin/creds
creds search tomcat

requirements.txt pins tinydb==4.3 and lists requests, prettytable and fire unpinned. The tinydb pin is the one to watch: it is a 2020-era release, so a modern Python environment may want a virtualenv rather than a system-wide install.

Updating the local database and exporting username and password lists

creds update checks for a newer dataset and downloads it. The README shows the sequence of messages: Check for new updates, then New updates are available, then [+] Download database. Because the update pulls from the network, it is the one operation that cannot be done air-gapped unless you move the CSV by hand.

bash
creds update
creds search tomcat export

Adding export to a search writes two files and prints their paths. In the README example they are /tmp/tomcat-usernames.txt and /tmp/tomcat-passwords.txt. This is the feature that connects the dataset to existing tooling: the exported lists feed a brute-force or password-spray step in whatever framework you already use. The README frames it that way, noting the export could be used for brute force attacks.

Both search and update accept a proxy. The README states the proxy option is only available from version 0.5.2, which matches the release list where creds-v0.5.2 is dated 2023-11-28.

bash
creds search tomcat --proxy=http://localhost:8080
creds update --proxy=http://localhost:8080
creds search tomcat --proxy=http://localhost:8080 export

If your engagement requires all traffic through an intercepting proxy, that flag is the reason to check the installed version first.

It does not scan, fingerprint or authenticate anything

This is the limitation that decides whether the tool fits. creds never touches a target host. It reads a local CSV, prints matching rows, and optionally writes two text files. There is no network discovery, no HTTP request to a device, no login attempt, no banner grab. If you need the tool to find the printers on a subnet and try the HP logins for you, that is changeme or routersploit, which the README credits as sources and links as automation options.

The practical consequence is that the hard part stays with you. Matching a row to a real device requires knowing the vendor and model, which usually means a separate fingerprinting step. The dataset also carries no version or firmware qualifier on rows, so a credential that was default on an older firmware may have been removed in a later one, and nothing in the CSV tells you which. And because the data is aggregated from third-party projects, a wrong row costs you time on a live test with no way to tell from the repository whether it was ever confirmed. Verify against vendor documentation before you make a finding out of a hit.

Pass Station: the same CSV with a different search model

The README highlights Pass Station, a CLI and library by noraj that reads DefaultCreds-Cheat-Sheet.csv directly. The difference is in the query and output layer rather than the data. Pass Station offers field selection, switches, regular expressions and highlighting, and it emits simple tables, pretty tables, JSON, YAML or CSV. creds offers one search term, one table format, and a two-file export.

So the choice is about how you consume the data. If you want to pipe results into another tool or filter on a specific column, Pass Station's structured output is the better fit. If you want a single installed command that prints a table and drops username and password files in /tmp, creds is shorter to operate. Both read the same CSV, so a gap in the dataset is a gap in both; switching tools does not buy you coverage.

Maintenance, licence and the cost of keeping the data current

The repository is not archived. The most recent push recorded for it is 2026-07-09. The release cadence is slow and irregular: creds-v0.5.3 is dated 2025-03-08, creds-v0.5.2 is dated 2023-11-28, and creds-0.5.1 is dated 2023-11-12. The setup.py version is 0.5.3, matching the latest release tag. So the code changes rarely, and the value of the project lives in the CSV, which moves independently of releases through creds update and through pull requests.

That split defines the upgrade cost. Upgrading the Python package is a pip operation you will rarely need to repeat. Keeping the data fresh is a recurring one: run creds update before an engagement, or pull the repository, because a stale local copy silently under-reports. There is no changelog described in the README for dataset changes, so you cannot diff what a given update added.

The licence is MIT, which permits commercial and internal use with the copyright notice retained. The README carries a disclaimer that the material is for educational purposes and used at your own responsibility. That disclaimer is not a legal opinion on your engagement; authorisation to test a device comes from the asset owner, not from the tool's licence.

Editorial conclusion

Adopt it if you are a pentester or blue teamer who needs a fast, offline lookup of vendor default logins and a way to export username and password lists for an authorised test. Do not adopt it if you expect it to discover devices, attempt logins or scan a network on its own; it is a dataset with a search command. Before relying on it, open DefaultCreds-Cheat-Sheet.csv and check that the vendors in your inventory are present, then run creds update on the machine that will use it and confirm the export files land where your tooling expects.

Frequently asked questions

Can you give me an example of a default password from DefaultCreds-cheat-sheet?

The README's own example output shows apache tomcat (web) with the username tomcat and the password tomcat, and another row with admin and admin. The dataset's most frequent password value is a blank entry, appearing 479 times.

How do I find the default password for a product with DefaultCreds-cheat-sheet?

Install the package and run creds search followed by the product name, for example creds search tomcat. The command prints a table of matching Product, username and password rows from the local CSV.

What is the risk of using a default password?

The README frames default credentials as a security flaw that blue teamers should discover on company infrastructure assets so it can be mitigated, and points to the OWASP WSTG-ATHN-02 test for default credentials as the methodology.

Official sources

  1. ihebski/DefaultCreds-cheat-sheet on GitHub
  2. License: MIT
  3. Project website
  4. README
  5. Releases
Add this badge to your README

If you maintain this project, the badge below links readers to this analysis and shows its maintenance status from the daily GitHub snapshot. Paste the markdown into your README; add ?metric=license or ?metric=stars to the image URL for a different field.

Add this badge to your README

markdown
[![Hysen Labs](https://hysenlabs.com/badge/ihebski-defaultcreds-cheat-sheet.svg)](https://hysenlabs.com/projects/ihebski-defaultcreds-cheat-sheet)