Recon & OSINT
Subfinder
Passive subdomain discovery at scale.
osintdnsrecon
subfinder — terminal
$ subfinder -d example.com -silentWhat it does
Subfinder enumerates subdomains using passive online sources, returning results fast without sending traffic to the target. A staple first step in external reconnaissance.
Common use cases
- •Fast passive subdomain discovery during the reconnaissance phase of a pentest.
- •Enumerate subdomains for a bug bounty target without sending traffic to origin servers.
- •Feed discovered subdomains into other tools like dnsx and httpx for live host filtering.
Key features
- •Entirely passive enumeration — no direct traffic to the target.
- •Integrates with 30+ public sources including CertSpotter, AlienVault, and SecurityTrails.
- •Designed for easy piping into other ProjectDiscovery tools.
- •Supports wildcard filtering and recursive enumeration.
Source
https://github.com/projectdiscovery/subfinder ↗More Recon & OSINT tools
Need hosted scanning instead of local tooling?
Run a scan in the browser →