Tools for subdomain brute forcing

This page summarizes the projects mentioned and recommended in the original post on /r/hacking

Our great sponsors
  • InfluxDB - Power Real-Time Data Analytics at Scale
  • WorkOS - The modern identity platform for B2B SaaS
  • SaaSHub - Software Alternatives and Reviews
  • amass

    In-depth attack surface mapping and asset discovery

  • Amass = https://github.com/OWASP/Amass

  • Sublist3r

    Fast subdomains enumeration tool for penetration testers

  • sublist3r = https://github.com/aboul3la/Sublist3r

  • InfluxDB

    Power Real-Time Data Analytics at Scale. Get real-time insights from all types of time series data with InfluxDB. Ingest, query, and analyze billions of data points in real-time with unbounded cardinality.

    InfluxDB logo
  • puredns

    Puredns is a fast domain resolver and subdomain bruteforcing tool that can accurately filter out wildcard subdomains and DNS poisoned entries.

  • massdns

    A high-performance DNS stub resolver for bulk lookups and reconnaissance (subdomain enumeration)

  • MassDNS = https://github.com/blechschmidt/massdns

  • gobuster

    Directory/File, DNS and VHost busting tool written in Go

  • GoBuster = https://github.com/OJ/gobuster

  • reconftw

    reconFTW is a tool designed to perform automated recon on a target domain by running the best set of tools to perform scanning and finding out vulnerabilities

  • reconFTW = https://github.com/six2dez/reconftw

  • subscraper

    Subdomain and target enumeration tool built for offensive security testing

  • subscraper = https://github.com/m8sec/subscraper

  • WorkOS

    The modern identity platform for B2B SaaS. The APIs are flexible and easy-to-use, supporting authentication, user identity, and complex enterprise features like SSO and SCIM provisioning.

    WorkOS logo
NOTE: The number of mentions on this list indicates mentions on common posts plus user suggested alternatives. Hence, a higher number means a more popular project.

Suggest a related project

Related posts