the-art-of-subdomain-enumeration icon indicating copy to clipboard operation
the-art-of-subdomain-enumeration copied to clipboard

This repository contains all the supplement material for the book "The art of sub-domain enumeration"

The art of subdomain enumeration

  • This repository contains all the supplement material for the book "The art of subdomain enumeration"
  • The book is available here: https://appsecco.com/books/subdomain-enumeration/
  1. censys_subdomain_enum.py - Extract subdomains for a given domain using Censys.io API
  2. cheatsheet.pdf - cheat sheet for the subdomain enumeration techniques
  3. cloudflare_subdomain_enum.py - A script to do DNS enumeration using Cloudflare service
  4. crtsh_enum_psql.py - Extract subdomains for a given domain using crt.sh postgres interface(Python)
  5. crtsh_enum_psql.sh - Extract subdomains for a given domain using crt.sh postgres interface(shell script)
  6. crtsh_enum_web.py - Extract subdomains for a given domain using crt.sh by scraping the web page(Python3)
  7. san_subdomain_enum.py - Extract domains/subdomains listed in Subject Alternate Name(SAN) of SSL/TLS cert for a domain
  8. virustotal_subdomain_enum.py - Extract subdomains for a given domain using VirusTotal API

Feedback/Suggestions

@0xbharath