VulnScanners Logo

Recon & OSINT

Subfinder

Passive subdomain discovery at scale.

osintdnsrecon
subfinder — terminal
$ subfinder -d example.com -silent

What it does

Subfinder enumerates subdomains using passive online sources, returning results fast without sending traffic to the target. A staple first step in external reconnaissance.

Common use cases

  • Fast passive subdomain discovery during the reconnaissance phase of a pentest.
  • Enumerate subdomains for a bug bounty target without sending traffic to origin servers.
  • Feed discovered subdomains into other tools like dnsx and httpx for live host filtering.

Key features

  • Entirely passive enumeration — no direct traffic to the target.
  • Integrates with 30+ public sources including CertSpotter, AlienVault, and SecurityTrails.
  • Designed for easy piping into other ProjectDiscovery tools.
  • Supports wildcard filtering and recursive enumeration.

Source

https://github.com/projectdiscovery/subfinder

More Recon & OSINT tools

Need hosted scanning instead of local tooling?

Run a scan in the browser →