Subdomain Hunting

Google fu

site:tesla.com -www #Exclude www from result
site:tesla.com filetype:pdf

dnsrecon

dnsrecon -a -d tesla.com

sublist3r

sublist3r -d tesla.com -t 100

crt.sh

certificate finger printing

amass

(gather intel)
amass intel -d example.com 

(get subdomains)
amass -d example.com -include subdomains 

(specify ip ranges)
amass -d example.com -addr <IP>/<CIDR> 

(scan ASNs)
amass intel -asn <ASN>

(scan domain that response to DNS querires)
amass intel -asn <ASN> -include subdomains -active -o output.txt 

(limit the number of DNS queries)
amass intel -asn <ASN> -max-dns-queries 1000 -o output.txt 

(save result)
-o output.txt 

(To just list subdomains)
amass enum -d tesla.com | grep tesla.com 

httprobe

bbot

subfinder

findomain

OneForAll

assetfinder

vita

theHarvester

gau :

fetches known URLs from AlienVault's Open Threat Exchange, the Wayback Machine, and Common Crawl for any given domain.

rapiddns + crt.sh

Last updated

Was this helpful?