Skip to content
Back to skills

Recon Subdomain Enum

ASecurity

Enumerate subdomains and live hosts to build the attack surface for a bug-bounty program or external assessment. Load at engagement start, on "recon", a root domain in scope, "find subdomains", or before content discovery. Signals: wildcard scope (*.target.com), a program scope list, a new external target.

  • 20 stars
  • 0 votes
  • 0 copies
  • 0 views
  • Added September 22, 2026
ai-agentsrustgo

Security analysis

A100/100

Scanned September 22, 2026

npx -y skills add NoorQureshi/SploitAgent --skill recon-subdomain-enum --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Recon Subdomain Enum?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Recon Subdomain Enum
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/noorqureshi-recon-subdomain-enum/badge)](https://www.skillsdirectory.com/skills/noorqureshi-recon-subdomain-enum)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: recon-subdomain-enum
description: >
  Enumerate subdomains and live hosts to build the attack surface for a bug-bounty program or
  external assessment. Load at engagement start, on "recon", a root domain in scope, "find
  subdomains", or before content discovery. Signals: wildcard scope (*.target.com), a program
  scope list, a new external target.
domain: recon
type: technique
stability: learning
modes: [bugbounty]
severity: info
mitre: [T1595, T1590]
tools: [subfinder, amass, dnsx, httpx, naabu]
schema_version: 1
---

# Subdomain & live-host enumeration

## When it applies
External, in-scope, wildcard programs where surface = subdomains. Do this before hunting;
most bugs live on forgotten hosts (staging, dev, legacy, acquisitions).

## Why it works
Organizations sprint faster than they inventory. Passive sources (CT logs, DNS aggregators)
plus permutation/brute-force surface hosts nobody remembers — and those skip the hardening
the flagship app got.

## Method
1. **Passive** (fast, quiet): `subfinder -d target.com -all -silent` and `amass enum -passive
   -d target.com`. Pulls CT logs, PassiveDNS, search engines — no packets to the target.
2. **Resolve & dedupe**: `dnsx -l subs.txt -a -resp -silent` to keep only records that resolve
   (drops dead CT noise) and grab their IPs.
3. **Brute/permute** for hidden hosts: `puredns`/`shuffledns` with a DNS wordlist + `dnsgen`
   permutations (`dev-`, `-staging`, region prefixes) against resolvers.
4. **Probe live web**: `httpx -l resolved.txt -sc -title -tech-detect -cdn -silent` → status,
   title, tech, CDN. This is your ranked target list.
5. **Port sweep** where allowed: `naabu -l hosts.txt -top-ports 1000` to find non-web services.

## Gotchas
- Wildcard DNS (`*.target.com` → one IP) creates false positives — filter with `dnsx`/`puredns`
  wildcard detection before trusting a hit.
- Confirm each host is **in program scope** before probing; out-of-scope acquisitions are a trap.
- CDN/WAF IPs are shared — don't port-scan Cloudflare ranges; find origin instead.

## Verify success
A deduplicated list of resolving, in-scope hosts with status/title/tech — the input to
content discovery and per-class hunting.

## References
ProjectDiscovery docs (subfinder/httpx/dnsx/naabu); OWASP Amass; TomNomNom recon workflow.

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…