OSINT
CtrlK
  • OSINT Complete Guide for Beginners
  • Search Engines and Google Dorking
  • Email/ Usernames /Passwords
  • Downloading Leaked Databases
  • Social Media
    • Instagram
    • Facebook
    • Tiktok
    • Twitter
    • Whatsapp
  • Image OSINT
  • Maps OSINT
  • Phone Numbers
  • People Search
  • Government Records
  • Website OSINT
    • Subdomains Enumeration
    • DNS Records
    • Web Archive
    • Reverse Google Analytics
    • Analyse Documents Metadata
    • Website Monitoring
    • Backlinks
  • Metadata
  • Threat Intelligence
  • Books Search
  • Sock Puppet
  • Darkweb
  • Cracking hashes
  • Misc Tools
  • AI Tools
  • Paid Platforms(Multi Services)
  • Case Studies
  • Tutorials
  • Forums
  • OSINT Courses
  • OSINT Frameworks/ Curated Lists
  • OSINT Books and Resources
Powered by GitBook
On this page
  • Google Dorks for Subdomain Enumeration
  • Finding Subdomains
  • Kali Tools (Subdomain Enumeration)
  • API Keys to increase your dataset
  • Check if subdomains are Alive
  • Screenshot Alive domains

Was this helpful?

  1. Website OSINT

Subdomains Enumeration

Google Dorks for Subdomain Enumeration

"certifiedhacker.com"
site:*.tryhackme.com
-site:www.tryhackme.com  site:*.tryhackme.com \\except main website

Finding Subdomains

LogoPentest-Tools.com | 25+ Online Penetration Testing ToolsPentest-Tools.com
LogoInternet Archive: Wayback Machine

Kali Tools (Subdomain Enumeration)

LogoGitHub - aboul3la/Sublist3r: Fast subdomains enumeration tool for penetration testersGitHub
LogoGitHub - owasp-amass/amass: In-depth Attack Surface Mapping and Asset DiscoveryGitHub
slow but good
Logosubfinder | Kali Linux ToolsKali Linux
LogoGitHub - tomnomnom/assetfinder: Find domains and subdomains related to a given domainGitHub
LogoGitHub - incogbyte/shosubgo: Small tool to Grab subdomains using Shodan api.GitHub
Passive with shodan

API Keys to increase your dataset

LogoProjectdiscovery.io | Chaos
Paid
LogoNetlas.io - discover, research and monitor any assets available online
Paid

Check if subdomains are Alive

LogoGitHub - tomnomnom/httprobe: Take a list of domains and probe for working HTTP and HTTPS serversGitHub

Screenshot Alive domains

LogoInstallation ยท sensepost/gowitness WikiGitHub
PreviousWebsite OSINTNextDNS Records

Last updated 5 days ago

Was this helpful?