Subdomains Enumeration tools

Credit goes to respected owner's

Summary

  • Enumerate all subdomains

    • Subbrute

    • KnockPy

    • GoogleDorks

    • EyeWitness

    • Sublist3r

    • Subfinder

    • Findomain

    • Aquatone (Ruby and Go versions)

    • AltDNS

    • MassDNS

    • Nmap

    • Dnsdumpster

  • Subdomain take over

    • tko-subs

    • HostileSubBruteForcer

    • SubOver

Enumerate all subdomains (only if the scope is *.domain.ext)

Using Subbrute

Using KnockPy with Daniel Miessler’s SecLists for subdomain "/Discover/DNS"

Using EyeWitness and Nmap scans from the KnockPy and enumall scans

Using Google Dorks and Google Transparency Report

You need to include subdomains ;) https://www.google.com/transparencyreport/https/ct/?hl=en-US#domain=[DOMAIN]g&incl_exp=true&incl_sub=true

Using Sublist3r

Using Subfinder

Using Findomain

Using Aquatone - old version (Ruby)

Alternatively, you can use the Docker imagearrow-up-right provided by txt3rob.

Using Aquatone - new version (Go)

Using AltDNS

It's recommended to use massdns in order to resolve the result of AltDNS

Alternatively you can use goaltdnsarrow-up-right

Using MassDNS

Using Nmap

Using dnsdumpster

Subdomain take over

Check Can I take over xyzarrow-up-right by EdOverflow for a list of services and how to claim (sub)domains with dangling DNS records.

Using tko-subs

Using HostileSubBruteForcer

Using SubOver

References

Last updated