amass
subfinder
amass | subfinder | |
---|---|---|
21 | 8 | |
11,367 | 9,486 | |
1.6% | 1.5% | |
6.9 | 9.4 | |
about 2 months ago | 12 days ago | |
Go | Go | |
GNU General Public License v3.0 or later | MIT License |
Stars - the number of stars that a project has on GitHub. Growth - month over month growth in stars.
Activity is a relative number indicating how actively a project is being developed. Recent commits have higher weight than older ones.
For example, an activity of 9.0 indicates that a project is amongst the top 10% of the most actively developed projects that we are tracking.
amass
-
OWASP Amass
The Amass tool is a perfect fit for the sub-techniques in the Search Open Technical Databases category which is part of the reconnaissance phase from the matrix above.
-
amass VS dmut - a user suggested alternative
2 projects | 29 Nov 2023
-
findomain VS amass - a user suggested alternative
2 projects | 24 Nov 2023
- In-depth attack surface mapping and asset discovery
- 10. 使用工具帮你进行开源情报收集
-
Looking for Recommendations for New Vulnerability & PHI/PII Scanner
OWASP Zap, OWASP Amass, OpenVAS Scanner
-
Can authenticated internet-facing web app be discovered if not indexed by search engines?
My main source is Certificate Transparency, which is kind of a database of TLS certs created so far. But use external tools like Subfinder or Amass.
-
Millions of .git folders exposed publicly by mistake
Scan our domains and infrastructure to reveal if we have exposed.git repositories and other critical infrastructure. You can scan your domains and subdomains with many tools such as Amass or dirsearch to name a couple.
-
Tools for subdomain brute forcing
Amass = https://github.com/OWASP/Amass
- RustScan/RustScan: 🤖 The Modern Port Scanner 🤖
subfinder
-
Subdomain.center – discover all subdomains for a domain
https://github.com/projectdiscovery/subfinder does this, but it explains all the methods and lets you choose to only do a passive scan.
-
Introducing Goctopus: open-source, state-of-the-art GraphQL endpoint discovery & fingerprinting tool.
Subdomain Enumeration: Goctopus uses DNS records APIs via subfinder to enumerate subdomains.
-
Subdomain enumeration.
Subfinder
-
Can authenticated internet-facing web app be discovered if not indexed by search engines?
My main source is Certificate Transparency, which is kind of a database of TLS certs created so far. But use external tools like Subfinder or Amass.
- Como saber todos os domínios que uma empresa tem?
- How to find out domain names registered by a particular domain registrar?
-
Intellingence-Resources
Subfinder - https://github.com/projectdiscovery/subfinder
-
Subdomain Enumeration
The best CLI tool for finding subdomains is subfinder. It is made by ProjectDiscovery who creates really powerful tools. They recently got funded $1.7 million so that the devs could work full time on developing and maintaining these tools.
What are some alternatives?
assetfinder - Find domains and subdomains related to a given domain
masscan - TCP port scanner, spews SYN packets asynchronously, scanning entire Internet in under 5 minutes.
httprobe - Take a list of domains and probe for working HTTP and HTTPS servers
theHarvester - E-mails, subdomains and names Harvester - OSINT
breach-parse - A tool for parsing breached passwords
nuclei - Fast and customizable vulnerability scanner based on simple YAML based DSL.
gowitness - 🔍 gowitness - a golang, web screenshot utility using Chrome Headless
spiderfoot - SpiderFoot automates OSINT for threat intelligence and mapping your attack surface.
subby - An uber fast and simple subdomain enumeration tool using DNS and web requests with support for detecting wildcard DNS records.
Network-segmentation-cheat-sheet - Best practices for segmentation of the corporate network of any company
certificate-transparency - Auditing for TLS certificates.