Subdomain Hunting
Google fu
site:tesla.com -www #Exclude www from result
site:tesla.com filetype:pdfdnsrecon
dnsrecon -a -d tesla.comsublist3r
sublist3r -d tesla.com -t 100crt.sh
certificate finger printingamass
(gather intel)
amass intel -d example.com
(get subdomains)
amass -d example.com -include subdomains
(specify ip ranges)
amass -d example.com -addr <IP>/<CIDR>
(scan ASNs)
amass intel -asn <ASN>
(scan domain that response to DNS querires)
amass intel -asn <ASN> -include subdomains -active -o output.txt
(limit the number of DNS queries)
amass intel -asn <ASN> -max-dns-queries 1000 -o output.txt
(save result)
-o output.txt
(To just list subdomains)
amass enum -d tesla.com | grep tesla.com httprobe
bbot
subfinder
findomain
OneForAll
assetfinder
vita
theHarvester
gau :
fetches known URLs from AlienVault's Open Threat Exchange, the Wayback Machine, and Common Crawl for any given domain.
rapiddns + crt.sh
Last updated
Was this helpful?