🌆Subdomain Enumeration

Subdomain Enumeration Tools

Below is a list of powerful subdomain enumeration tools that can aid in reconnaissance and penetration testing:

  1. Sublist3r - Fast subdomains enumeration tool for penetration testers

  2. Amass - In-depth Attack Surface Mapping and Asset Discovery

  3. massdns - A high-performance DNS stub resolver for bulk lookups and reconnaissance (subdomain enumeration)

  4. Findomain - The fastest and cross-platform subdomain enumerator, do not waste your time.

  5. Sudomy - Sudomy is a subdomain enumeration tool to collect subdomains and analyzing domains performing automated reconnaissance (recon) for bug hunting / pentesting

  6. chaos-client - Go client to communicate with Chaos DNS API. domained

  7. domained - Multi Tool Subdomain Enumeration

  8. bugcrowd-levelup-subdomain-enumeration - This repository contains all the material from the talk "Esoteric sub-domain enumeration techniques" given at Bugcrowd LevelUp 2017 virtual conference

  9. shuffledns - shuffleDNS is a wrapper around massdns written in Go that allows you to enumerate valid subdomains using active bruteforce as well as resolve subdomains with wildcard handling and easy input-output…

  10. censys-subdomain-finder - Perform subdomain enumeration using the certificate transparency logs from Censys.

  11. Turbolist3r - Subdomain enumeration tool with analysis features for discovered domains

  12. censys-enumeration - A script to extract subdomains/emails for a given domain using SSL/TLS certificate dataset on Censys

  13. tugarecon - Fast subdomains enumeration tool for penetration testers.

  14. as3nt - Another Subdomain ENumeration Tool

  15. Subra - A Web-UI for subdomain enumeration (subfinder)

  16. Substr3am - Passive reconnaissance/enumeration of interesting targets by watching for SSL certificates being issued

  17. domain - enumall.py Setup script for Regon-ng

  18. altdns - Generates permutations, alterations, and mutations of subdomains and then resolves them

  19. brutesubs - An automation framework for running multiple open sourced subdomain bruteforcing tools (in parallel) using your own wordlists via Docker Compose

  20. dns-parallel-prober - This is a parallelized domain name prober to find as many subdomains of a given domain as fast as possible.

  21. dnscan - dnscan is a python wordlist-based DNS subdomain scanner.

  22. knock - Knockpy is a python tool designed to enumerate subdomains on a target domain through a wordlist.

  23. hakrevdns - Small, fast tool for performing reverse DNS lookups enmass

  24. dnsx - Dnsx is a fast and multi-purpose DNS toolkit that allows you to run multiple DNS queries of your choice with a list of user-supplied resolvers.

  25. subfinder - Subfinder is a subdomain discovery tool that discovers valid subdomains for websites.

  26. assetfinder - Find domains and subdomains related to a given domain

  27. crtndstry - Yet another subdomain finder

  28. VHostScan - A virtual host scanner that performs reverse lookups

  29. scilla - Information Gathering tool - DNS / Subdomains / Ports / Directories enumeration

  30. sub3suite - A research-grade suite of tools for subdomain enumeration, intelligence gathering, and attack surface mapping.

Feel free to explore these tools and choose the one that best fits your needs for subdomain enumeration. Happy hunting!😄

Last updated

Was this helpful?