Subdomain Finder (2024)

Table of Contents
Parameters How it works References

Discover subdomains and determine the attack surface of an organization.

Finding subdomains is an important step in the information gathering phase of a penetration test. Subdomains are interesting because they point to various (less-known) applications and indicate different external network ranges used by the target company.

For instance, subdom1.company.com points to IP 1.1.1.1 and subdom2.company.com points to IP 2.2.2.2. Now you know two different IP ranges possibly owned by your target organization and you can extend the attack surface.

Furthermore, subdomains sometimes host 'non-public' applications (e.g. test, development, restricted) which are usually less secure than the public/official applications so they can be the primary attack targets.

Parameters

How it works

This tool uses multiple techniques to find subdomains such as:

  • Search Historical Subdomains in our database of cached subdomains

  • DNS records (NS, MX, TXT, AXFR)

  • DNS enumeration based on a specially chosen wordlist

  • Public search engine queries

  • Word mutation techniques

  • Searching in SSL certificates

  • Parsing HTML links

  • Reverse DNS on target IP ranges

  • Generates permutations and alterations of the subdomain names found so far in the scan

  • Searching in CNAME records

Subdomain Finder (2024)

References

Top Articles
Latest Posts
Article information

Author: Pres. Lawanda Wiegand

Last Updated:

Views: 5465

Rating: 4 / 5 (71 voted)

Reviews: 86% of readers found this page helpful

Author information

Name: Pres. Lawanda Wiegand

Birthday: 1993-01-10

Address: Suite 391 6963 Ullrich Shore, Bellefort, WI 01350-7893

Phone: +6806610432415

Job: Dynamic Manufacturing Assistant

Hobby: amateur radio, Taekwondo, Wood carving, Parkour, Skateboarding, Running, Rafting

Introduction: My name is Pres. Lawanda Wiegand, I am a inquisitive, helpful, glamorous, cheerful, open, clever, innocent person who loves writing and wants to share my knowledge and understanding with you.