Findomain is a subdomain discovery tool and DNS resolver used for mapping an organization's external attack surface. It functions as a DNS infrastructure analyzer that searches for registered subdomains associated with a root domain to uncover undocumented infrastructure and services.
The project includes an attack surface monitor that tracks changes to subdomains over time, using differential state monitoring to identify newly created or deleted assets. It provides real-time alerting via webhooks when changes in the monitored domain surface are detected.
The system performs high-speed DNS resolution using multi-threaded queries and custom DNS server integration. Its capabilities extend to capturing visual evidence of active web services through headless browser screenshotting and consolidating reconnaissance data by importing subdomain lists from external tools.