Menu
Host Subdomain Ip ASN

To continue giving your better experience please disable your adblocker thank you.

Host Subdomain Ip

To continue giving your better experience please disable your adblocker thank you.

Host Subdomain Ip ASN

To continue giving your better experience please disable your adblocker thank you.

Host Subdomain Ip ASN

To continue giving your better experience please disable your adblocker thank you.

Host Subdomain Ip ASN

To continue giving your better experience please disable your adblocker thank you.

Host Subdomain Ip ASN
Subdomain Enumerator tools

Enumerated domains management dashboard

  • Track your subdomains
  • Keep your scan records
  • Incredibly fancy dashboard
  • Multiple subdomain scanner tabs
  • Entirely free
  • Signup
Online Subdomain finder management dashboard
Sublist3r

Fast subdomains enumeration tool for penetration testers

Dnscan

Dnscan is a python wordlist-based DNS subdomain scanner

SubBrute

A DNS meta-query spider that enumerates DNS records, and subdomains.

DNS reconnaissance using Fierce

Fierce is a semi-lightweight scanner that helps locate non-contiguous IP space and hostnames against specified domains. It's really meant as a pre-cursor to nmap, unicornscan, nessus, nikto, etc, since all of those require that you already know what IP space you are looking for. This does not perform exploitation and does not scan the whole internet indiscriminately. It is meant specifically to locate likely targets both inside and outside a corporate network. Because it uses DNS primarily you will often find mis-configured networks that leak internal address space. That's especially useful in targeted malware.

Installing Fierce

$ pip3 install fierce

$ fierce -h

Features of Fierce
  • Traverse IPs near discovered domains
  • Attempt an HTTP connection on domains discovered
  • Zone transfers
Anubis information gathering tool

Anubis is a subdomain enumeration and information gathering tool. Anubis collates data from a variety of sources, including HackerTarget, DNSDumpster, x509 certs, VirusTotal, Google, Pkey, and NetCraft. Anubis also has a sister project, AnubisDB, which serves as a centralized repository of subdomains.

How to install Installing

Prerequisites

If you are Linux user, the following modules or libraries are also required:

sudo apt-get install python3-pip python-dev libssl-dev libffi-dev

pip3 install anubis-netsec

snap install anubis

Features of Anubis subdomain enumeration
  • AnubisDB
  • Advanced features like using nmap
  • Uses Shodan
Subdomain scanning using Nmap dns-brute

Nmap can Attempts to enumerate DNS hostnames by brute force guessing of common subdomains. With the dns-brute.srv argument, dns-brute will also try to enumerate common DNS SRV records. Wildcard records are listed as "*A" and "*AAAA" for IPv4 and IPv6 respectively.

The dns-brute module of nmap request the following.

  • coroutine
  • dns
  • io
  • math
  • rand
Lepus

Lepus is a utility for identifying and collecting subdomains for a given domain. Subdomain discovery is a crucial part during the reconnaissance phase. One of the strength of Lepus lies at Performing several checks on identified domains for potential subdomain-takeover vulnerabilities. The module is enabled with --takeover and is executed after all others. If such a vulnerability is identified, the results are printed in the output and in a .csv file in the respective project folder under the directory with the results. Checks are performed for the following services. Lepus performs the following. Services (Collecting subdomains from the below services) Dictionary mode for identifying domains (optional) Permutations on discovered subdomains (optional) Reverse DNS lookups on identified public IPs (optional)

Features of Lepus
  • Wildcard Identification
  • RDAP Lookups
  • Dictionary Mode
  • Permutations Mode
  • Reverse Mode
  • Portscan
  • Subdomain Takeover

Tools developed for subdomain finding

  • SubFinder

    SubFinder is a subdomain discovery tool that discovers valid subdomains for websites by using passive online sources. It has a simple modular architecture and has been aimed as a successor to sublist3r project. SubFinder uses Passive Sources, Search Engines, Pastebins, Internet Archives, etc to find subdomains and then it uses a permutation module inspired by altdns to generate permutations and resolve them quickly using a powerful bruteforcing engine. It can also perform plain bruteforce if needed. The tool is highly customizable, and the code is built with a modular approach in mind making it easy to add functionalities and remove errors

    Last update Feb-26-2019

    Repository

    Written in Go programming

  • RED HAWK

    All in one tool for Information Gathering, Vulnerability Scanning and Crawling. A must have tool for all penetration testers

    Last update May-22-2019

    Repository

    Written in PHP

  • Th3inspector

    Th3inspector best tool for Information Gathering All in one tool for Information Gathering

    Last update Jul 1, 2018

    Repository

    Written in Perl

  • SubDomainizer

    SubDomainizer is a tool designed to find hidden subdomains and secrets present is either webpage, Github, and external javascripts present in the given URL. This tool also finds S3 buckets, cloudfront URL's and more from those JS files which could be interesting like S3 bucket is open to read/write, or subdomain takeover and similar case for cloudfront. It also scans inside given folder which contains your files.

    Last update May 16, 2019

    Repository

    Written in Python

  • censys-subdomain-finder

    This is a tool to enumerate subdomains using the Certificate Transparency logs stored by Censys. It should return any subdomain who has ever been issued a SSL certificate by a public CA

    Last update Aug 9, 2018

    Repository

    Written in Python

  • PentestEr_Fully-automatic-scanner

    DNS Subdomain ● Brute force ● Web Spider ● Nmap Scan ● etc

    Last update Jul 11, 2018

    Repository

    Written in Python

  • Rock-ON

    Rock-On is a all in one recon tool that will help your Recon process give a boost. It is mainley aimed to automate the whole process of recon and save the time that is being wasted in doing all this stuffs manually. A thorough blog will be up in sometime. Stay tuned for the Stable version with a UI.

    Last update Jul 9, 2019

    Repository

    Written in Ruby and Bash script

  • Subscraper

    SubScraper uses DNS brute force, Google & Bing scraping, and DNSdumpster to enumerate subdomains of a given host. Written in Python3, SubScraper performs HTTP(S) requests and DNS "A" record lookups during the enumeration process to validate discovered subdomains. This provides further information to help prioritize targets and aid in potential next steps. Post-Enumeration, "CNAME" lookups are displayed to identify subdomain takeover opportunities.

    Last update Aug 18, 2019

    Repository

    Written in Python

  • Horn3t

    Horn3t is your Nr #1 tool for exploring subdomains visually. Building on the great Sublist3r framework (or extensible with your favorite one) it searches for subdomains and generates awesome picture previews. Get a fast overview of your target with http status codes, add custom found subdomains and directly access found urls with one click.

    Last update Jun 6, 2019

    Repository

    Written in Python

  • Dnscan

    dnscan is a python wordlist-based DNS subdomain scanner. The script will first try to perform a zone transfer using each of the target domain's nameservers. If this fails, it will lookup TXT and MX records for the domain, and then perform a recursive subudomain scan using the supplied wordlist.

    Last update Aug 2, 2019

    Repository

    Written in Python

  • Gorecon

    Gorecon is a All in one Reconnaissance Tool , a.k.a swiss knife for Reconnaissance , A tool that every pentester/bughunter might wanna consider into their arsenal

    Last update Jun 21, 2019

    Repository

    Written in Go programming

  • Delator

    DELATOR (lat. informer) is a tool to perform subdomain enumeration and initial reconnaissance through the abusing of certificate transparency (CT) logs. It expands on the original work done by Sheila A. Berta with her CTFR tool and leverages the speed and power of Go.

    Last update Apr 10, 2019

    Repository

    Written in Go programming

  • findSubDomains

    A tool finding sub-domains for penetesters

    Last update July 28, 2019

    Repository

    Written in Python

  • Subrake

    A Powerful Subdomain Scanner & Validator Written in sockets which makes it a lot more faster and easier to manage. It works by enumerating subdomains by searching them on web and by using local wordlists. It further identify the assets of a domain based on their ip and CNAME records and identify subdomains which are using the same IP addresses. It also scan ports if are given and enumerte possible server engines used on assets using the SERVER header returned in the response. It also enumerates possible returned HTTP status codes on port 80 and 443

    Last update July 24, 2019

    Repository

    Written in Python

  • BlackBird Subdmaon Enumerator

    Blackbird was designed to automate and handle the heavy lifting of recon for large domains. It currently uses the following tools to do the following functionalities. Blackbird also uses a slack legacy token to alert you whenever a certain segment from the functionalities listed above has been started or is finsihed. Finally you can also choose to run the BlackBird API, the API allows you to launch the scanner from slack or any other tool of choice!

    Last update Mar 27, 2019

    Repository

    Written in Bash Shell

  • WHK Subdomains Scanner

    WSS (WHK Subdomains Scanner) es una herramienta diseñada para pentesters, la cual realiza búsqueda de subdominios y realiza acciones sobre cada nombre de dominio encontrado

    Last update Jul 4, 2019

    Repository

    Written in Python

  • Dnssubminer

    Python DNS Subdomain Miner. Includes GeoLite data created by MaxMind.

    Last update Mar 13, 2018

    Repository

    Written in Python