πŸ” Subdomain Enumeration & DNS

Subdomain enumeration and DNS brute-forcing are critical steps to discover the hidden components of a target’s infrastructure.

Tool Catalog

Select a tool below to view detailed specifications, cheatsheets, or definitions.

🧭

Subfinder

Fast passive subdomain discovery tool leveraging public search API engines.

View Wiki β†’
🌐

OWASP Amass

Comprehensive active/passive subdomain mapper and DNS tracking framework.

View Wiki β†’
πŸ”Ž

Assetfinder

Lightweight Go tool to quickly discover domains and subdomains related to a target.

πŸ”€

Shuffledns / Massdns

High-performance resolver engines designed to process millions of DNS queries using custom wordlists.

πŸ“‘

DNSx

ProjectDiscovery's DNS resolution utility that allows bulk checking and brute force permutation.

πŸ”’

Puredns

Python/Go wrapper around massdns designed to filter out wildcards and false positives.

πŸŒ€

Altdns / Gotator

Subdomain permutation and alteration generator engines that create word combinations based on target structures.

πŸ“œ

crt.sh

SSL/TLS certificate database scraper to identify hidden domains from old SSL registrations.

☁️

Chaos

ProjectDiscovery API dataset client offering pre-compiled lists of active internet domains.


πŸ”— Back to Toolkit