For a tool for subdomain enumeration and reconnaissance, the strongest matches are ice3man543/subfinder (Subfinder is a passive subdomain enumeration tool that queries), owasp/amass (Amass is a comprehensive network attack surface mapper that) and aboul3la/sublist3r (Sublist3r discovers subdomains through both passive API queries and). blacklanternsecurity/bbot and six2dez/reconftw round out the shortlist. Each is ranked by relevance to your query, popularity and recent activity.
Identify subdomains and map external attack surfaces using automated discovery and reconnaissance security utilities.
Subfinder is a passive subdomain enumeration tool and DNS discovery utility designed to identify valid subdomains and hostnames associated with a specific organization or domain. It functions as a passive reconnaissance tool, gathering information about target domains by querying online databases without sending network traffic to the target infrastructure. The tool utilizes a pluggable provider architecture to separate discovery logic into independent modules, allowing for the integration of multiple passive-source APIs. It employs a concurrent-worker request model to execute network request
Subfinder is a passive subdomain enumeration tool that queries online databases to discover subdomains without sending traffic, making it a solid fit for the passive discovery aspect of the search, though it lacks active scanning, port probing, and screenshot features.
Amass is a network attack surface mapper and reconnaissance framework designed to discover and map the external, internet-facing infrastructure of a target organization. It functions as an open source intelligence tool that identifies public network boundaries and locates hidden or forgotten subdomains to define an organization's total reachable footprint. The project utilizes passive-source data aggregation from external APIs and public databases alongside active DNS brute-forcing and recursive subdomain expansion. It employs a graph-based asset mapping system to visualize the relationships
Amass is a comprehensive network attack surface mapper that discovers subdomains through both passive and active techniques, performs DNS resolution, and maps relationships graphically—making it a strong fit for your subdomain enumeration and attack surface mapping needs.
Sublist3r is a subdomain enumeration tool and passive reconnaissance framework designed to discover subdomains by querying search engines and public intelligence sources. It functions as a security tool for identifying the digital footprint of a target domain. The project provides both passive enumeration through multi-source API aggregation and active discovery via a DNS brute force tool. It includes a TCP port scanner to identify active services and open ports on discovered subdomains, facilitating attack surface mapping. The tool can be used as a standalone utility or as a Python security
Sublist3r discovers subdomains through both passive API queries and active brute forcing, and includes a TCP port scanner for mapping services, but does not handle screenshot or technology detection for visual attack surface mapping.
This project is an open-source intelligence reconnaissance framework and recursive attack surface mapper. It functions as a containerized security scanner designed to map public-facing infrastructure, perform subdomain enumeration, and automate the gathering of open-source intelligence. The system employs a recursive discovery engine to iteratively explore target infrastructure, utilizing a plugin-based module architecture to extend scanning capabilities. It integrates third-party APIs for data enrichment and applies YARA rules across discovered assets to identify specific vulnerability patte
BBOT is an OSINT reconnaissance framework purpose-built for recursive subdomain enumeration and attack surface mapping, with built-in support for passive/active discovery, DNS verification, port scanning, screenshot capture, and JSON output — directly matching this search's requirements.
reconftw is an attack surface management framework and reconnaissance workflow orchestrator designed to automate the discovery, mapping, and monitoring of external digital assets. It operates as a modular tool-chain pipeline that coordinates a sequence of security tools to perform intelligence gathering and vulnerability scanning. The project distinguishes itself through a cloud-native deployment model that parallelizes scanning workloads across a fleet of remote VPS instances to bypass local resource constraints. It utilizes container-based environment isolation to ensure consistent executio
reconftw is an automated attack surface management framework that orchestrates multiple tools for passive and active subdomain discovery, DNS verification, port scanning, and more, giving you a complete reconnaissance pipeline exactly matching this search.
Sn1per is a vulnerability management platform and penetration testing orchestrator designed to automate reconnaissance, vulnerability scanning, and exploit verification. It functions as a dockerized security toolkit that coordinates multiple tools into a unified automated pipeline to identify security flaws across network and web assets. The platform features an attack surface manager for discovering internet-facing assets through OSINT, DNS enumeration, and certificate transparency. It distinguishes itself with an AI-powered security analyzer that uses large language models to summarize scan
Sn1per is a Dockerized penetration testing orchestrator that automates reconnaissance and attack surface discovery — it includes passive and active subdomain enumeration, DNS resolution, port scanning, screenshot capture, and an AI-powered analysis pipeline, directly matching the subdomain and attack surface mapping focus of this search.
Rengine is an automated reconnaissance framework and vulnerability management platform designed for attack surface monitoring. It functions as a centralized hub for discovering subdomains and open ports, gathering open-source intelligence, and tracking security flaws across target networks. The system integrates large language models to analyze reconnaissance data and generate vulnerability descriptions and insights. It distinguishes itself through a plugin-based tool integration that wraps external security scanning binaries and a target mapping system that tracks changes to assets over time
Rengine is an automated reconnaissance framework specifically built for subdomain enumeration, port scanning, OSINT gathering, and attack surface mapping, with plugin support for external tools and output to JSON, making it a comprehensive fit for this search.
Findomain is a subdomain discovery tool and DNS resolver used for mapping an organization's external attack surface. It functions as a DNS infrastructure analyzer that searches for registered subdomains associated with a root domain to uncover undocumented infrastructure and services. The project includes an attack surface monitor that tracks changes to subdomains over time, using differential state monitoring to identify newly created or deleted assets. It provides real-time alerting via webhooks when changes in the monitored domain surface are detected. The system performs high-speed DNS r
Findomain is a dedicated subdomain discovery and attack surface mapping tool that performs passive OSINT and active DNS resolution, tracks asset changes over time, and supports browser screenshots and webhooks, though it may not include built-in port scanning or full web technology detection as part of its core feature set.
Subfinder is a passive subdomain enumeration tool and DNS asset discovery utility designed for mapping the external attack surface of a domain. It functions as a passive reconnaissance framework that identifies subdomains by querying curated third-party data sources and APIs without interacting directly with the target infrastructure. The tool utilizes a modular provider interface to integrate various passive sources and employs concurrent request orchestration to manage simultaneous network queries. It includes wildcard DNS filtering to identify and remove catch-all records, ensuring the res
Subfinder is a dedicated passive subdomain enumeration and DNS asset discovery tool for mapping external attack surfaces, fitting your core need but lacking active discovery, port scanning, and visual mapping features.
Amass is an attack surface management tool designed to identify, map, and inventory an organization's internet-facing digital assets. It functions as a security asset discovery engine that systematically expands an organization's known infrastructure footprint through recursive domain name resolution and the collection of intelligence from diverse public data sources. The platform distinguishes itself by utilizing a graph-based modeling approach to organize discovered resources. By maintaining a persistent graph database, it tracks the relationships between infrastructure components and norma
Amass is an attack surface management tool that performs passive and active subdomain discovery, DNS resolution, and graph-based mapping of discovered assets, making it a comprehensive answer for subdomain enumeration and attack surface mapping.
SpiderFoot is an open-source reconnaissance and intelligence automation framework designed to streamline the collection and correlation of data for security investigations. It functions as a comprehensive platform that automates the querying of hundreds of public data sources to map digital footprints, identify exposed assets, and uncover potential security threats across an organization's external perimeter. The platform distinguishes itself through a modular, plugin-based architecture that executes data gathering tasks in parallel, supported by a directed graph data model that tracks relati
SpiderFoot is a reconnaissance automation framework that actively and passively discovers subdomains, resolves DNS, integrates port scanning, and maps the attack surface through a modular plugin system and graph visualization, making it a comprehensive tool for this search.
Anubis is a command-line security reconnaissance framework designed for subdomain enumeration and attack surface mapping. It functions as a utility for security professionals to identify, catalog, and visualize the external digital footprint of an organization by discovering all subdomains associated with a target domain. The tool distinguishes itself through a modular resolver pipeline that integrates passive reconnaissance from third-party security APIs and public certificate transparency logs. It combines this data with active discovery methods, including recursive DNS brute-forcing and al
Anubis is a command-line security reconnaissance framework purpose-built for subdomain enumeration and attack surface mapping, combining passive API intelligence with active brute-forcing via a modular resolver pipeline—exactly the kind of tool this search asks for, even if it doesn't cover every listed advanced feature like port scanning or screenshot capture.
theHarvester is a command-line utility designed for gathering open-source intelligence and mapping an organization's external attack surface. It functions as a security information gathering framework that automates the collection of publicly available data to assist in reconnaissance and threat analysis. The tool utilizes a plugin-based architecture to execute isolated queries against various search engines and public databases. It employs asynchronous task execution to run multiple discovery operations in parallel, while a centralized pipeline aggregates and deduplicates findings from these
theHarvester is an OSINT reconnaissance tool that discovers subdomains and maps an organization's external attack surface via passive search-engine queries and public databases, fitting the core requirement even though it lacks integrated port scanning and visual mapping features.
Photon is a command-line web crawler designed for security reconnaissance and information gathering. It systematically traverses websites to discover URLs, map domain infrastructure, and identify associated subdomains by retrieving DNS records. The tool distinguishes itself through its ability to perform deep content analysis, including the extraction of sensitive data such as API keys and authentication tokens using user-defined regular expressions. It supports offline inspection by cloning crawled web content to the local filesystem, allowing for structural analysis without additional netwo
Photon is a security reconnaissance web crawler that maps domain infrastructure and identifies subdomains via DNS record retrieval, fitting the subdomain enumeration and attack surface mapping category, though it lacks port scanning, screenshotting, and visual mapping features.
Argus is a modular network reconnaissance framework designed for gathering network intelligence, mapping infrastructure, and assessing security postures through automated discovery tasks. It operates as a containerized security toolset that allows for the consistent execution of specialized information-gathering modules across different operating systems. The system functions as an infrastructure audit tool and a web application security scanner, performing tasks such as DNS lookups, port scanning, and the inspection of HTTP headers to detect vulnerabilities. It also serves as a threat intell
Argus is a modular network reconnaissance framework that performs DNS lookups, port scanning, CMS detection, and OSINT gathering, making it a solid fit for subdomain enumeration and attack surface mapping, though it may lack explicit visual mapping and screenshot features.
Subfinder is a security reconnaissance framework designed for subdomain enumeration and attack surface management. It functions as a discovery engine that identifies and maps internet-exposed infrastructure, cloud-hosted assets, and network ranges to maintain a comprehensive inventory of an organization's digital footprint. The project distinguishes itself through a modular, template-driven scanning engine that executes security checks against discovered assets. It leverages cloud-native asset discovery to query provider APIs and infrastructure metadata, while supporting distributed agent orc
Subfinder is a dedicated subdomain enumeration framework that discovers internet-exposed assets through multiple passive and active sources, fitting the core need for subdomain discovery and attack surface mapping, though it focuses on discovery and resolution rather than the full set of scanning and visualization features you listed.
Knock is an attack surface management tool and DNS reconnaissance framework used for discovering and mapping an organization's external infrastructure. It functions as a subdomain enumeration tool and HTTP security scanner to identify reachable hosts and organizational assets. The project distinguishes itself by using a passive-active hybrid enumeration strategy, combining external API lookups with active wordlist brute-force attacks and DNS zone transfers. It includes a multi-stage validation pipeline that detects DNS wildcard records and verifies host connectivity to filter out false positi
Knock is a Python-based subdomain scanner that performs subdomain enumeration, fitting the reconnaissance need, but it lacks the broader attack surface mapping features like port scanning and screenshot detection described in the request.
Find domains and subdomains related to a given domain
Assetfinder is a lightweight command-line tool that finds subdomains related to a domain using passive sources, making it a solid fit for the subdomain enumeration part of your intent, but it lacks active discovery, port scanning, and visual mapping features.
SubDomainizer is a security scanning utility designed to map web infrastructure and identify sensitive information exposure. It functions as a reconnaissance tool that aggregates data from web pages, local files, and remote code hosting services to provide a comprehensive assessment of a target's attack surface. The tool specializes in discovering hidden subdomains and infrastructure entry points through recursive web crawling and the analysis of SSL certificate metadata. It further secures environments by scanning source code and external repositories for exposed API keys, passwords, and oth
Subdomainizer is a security tool that enumerates subdomains and uncovers secrets, cloud storage, and interesting endpoints from external JavaScript, files, and GitHub, covering subdomain enumeration and attack surface mapping but lacking port scanning, screenshots, and visual mapping features.
ScopeSentry is a distributed attack surface management platform designed to catalog digital assets and automate security assessments across large network environments. It functions as a network asset discovery tool and vulnerability scanner, providing a framework for maintaining visibility over organizational infrastructure. The platform distinguishes itself through a distributed architecture that orchestrates worker nodes to execute security tasks in parallel. It utilizes an event-driven discovery process to identify new assets and subdomains, maintaining a stateful record of configurations
ScopeSentry is a dedicated attack-surface mapping tool that combines subdomain enumeration, port scanning, and vulnerability scanning with distributed-node support, covering core reconnaissance needs even if screenshot and web technology detection are not explicitly mentioned.
| Repository | Stars | Language | License | Last push |
|---|---|---|---|---|
| ice3man543/subfinder | 13.9K | Go | MIT | |
| owasp/amass | 14.7K | Go | NOASSERTION | |
| aboul3la/sublist3r | 11K | Python | GPL-2.0 | |
| blacklanternsecurity/bbot | 9.9K | Python | AGPL-3.0 | |
| six2dez/reconftw | 7.2K | Shell | mit | |
| 1n3/sn1per | 10K | Shell | other | |
| yogeshojha/rengine | 8.5K | HTML | gpl-3.0 | |
| findomain/findomain | 3.7K | Rust | gpl-3.0 | |
| subfinder/subfinder | 13.9K | Go | MIT | |
| owasp-amass/amass | 14.2K | Go | other |