Performing Subdomain Enumeration With Subfinder
Overview
Cybersecurity skill for performing subdomain enumeration with subfinder. Follows industry best practices and security standards.
When to Use
Trigger phrases:
"performing subdomain enumeration with subfinder"
"Enumerate subdomains of target domains using ProjectDiscovery's Subfinder passiv"
During the reconnaissance phase of penetration testing or bug bounty hunting
When mapping the external attack surface of a target organization
Before performing vulnerability scanning on discovered subdomains
When building an asset inventory for continuous security monitoring
During red team engagements requiring passive information gathering
When NOT to Use
- When you lack proper authorization for testing
- For production systems without change management
- When the task requires legal or compliance expertise beyond technical scope
Prerequisites
- Go 1.21+ installed for building from source
- Subfinder v2 installed (
go install -v github.com/projectdiscovery/subfinder/v2/cmd/subfinder@latest)
- API keys configured for passive sources (Shodan, Censys, VirusTotal, SecurityTrails, Chaos)
- Provider configuration file at
$HOME/.config/subfinder/provider-config.yaml
- Network access to passive DNS and certificate transparency sources
- httpx or httprobe for validating discovered subdomains
Workflow
# Example: IOC detection
import re
IOC_PATTERNS = {
"ip": r"\b(?:\d{1,3}\.){3}\d{1,3}\b",
"domain": r"\b[a-z0-9-]+\.[a-z]{2,}\b",
"hash_md5": r"\b[a-f0-9]{32}\b",
"hash_sha256": r"\b[a-f0-9]{64}\b",
}
def extract_iocs(text: str) -> dict:
return {k: re.findall(v, text) for k, v in IOC_PATTERNS.items()}
- Plan Operations — Define objectives, scope, and success criteria for subdomain enumeration operations.
- Prepare Environment — Set up tools, access, and data sources required for subdomain enumeration.
- Execute Core Workflow — Use subfinder to perform subdomain enumeration operations following established procedures.
- Validate Results — Verify that results meet quality standards and objectives.
- Report Findings — Document results, observations, and recommendations.
- Follow Up — Track remediation actions and verify fixes where applicable.
Tools
- subfinder — Primary tool for this skill
- Analysis Platform — Data processing and visualization
- Collaboration Tools — Team coordination and knowledge sharing
Process
- Design — Define interface, identify patterns, plan implementation
- Implement — Write code following existing conventions, add tests
- Verify — Run tests, check integration, validate behavior
Verification
Anti-Rationalization Table
| Rationalization |
Reality |
| "We are too small to be targeted" |
Automated attacks target everyone. Size does not matter. |
| "Security slows us down" |
A breach slows you down 100x more. Build security in from the start. |
| "We will fix it after launch" |
Vulnerabilities in production are exploited within hours. Fix before deploy. |
1---2name: performing-subdomain-enumeration-with-subfinder3description: Use when enumerate subdomains of target domains using ProjectDiscovery's Subfinder passive reconnaissance tool to map the attack surface during security assessments. Use when working with performing subdomain enumeration with subfinder.4license: Apache-2.05---67# Performing Subdomain Enumeration With Subfinder89## Overview1011Cybersecurity skill for performing subdomain enumeration with subfinder. Follows industry best practices and security standards.1213## When to Use14**Trigger phrases:**15- "performing subdomain enumeration with subfinder"16- "Enumerate subdomains of target domains using ProjectDiscovery's Subfinder passiv"1718- During the reconnaissance phase of penetration testing or bug bounty hunting19- When mapping the external attack surface of a target organization20- Before performing vulnerability scanning on discovered subdomains21- When building an asset inventory for continuous security monitoring22- During red team engagements requiring passive information gathering232425## When NOT to Use2627- When you lack proper authorization for testing28- For production systems without change management29- When the task requires legal or compliance expertise beyond technical scope303132## Prerequisites33- Go 1.21+ installed for building from source34- Subfinder v2 installed (`go install -v github.com/projectdiscovery/subfinder/v2/cmd/subfinder@latest`)35- API keys configured for passive sources (Shodan, Censys, VirusTotal, SecurityTrails, Chaos)36- Provider configuration file at `$HOME/.config/subfinder/provider-config.yaml`37- Network access to passive DNS and certificate transparency sources38- httpx or httprobe for validating discovered subdomains3940## Workflow4142```python43# Example: IOC detection44import re4546IOC_PATTERNS = {47 "ip": r"\b(?:\d{1,3}\.){3}\d{1,3}\b",48 "domain": r"\b[a-z0-9-]+\.[a-z]{2,}\b",49 "hash_md5": r"\b[a-f0-9]{32}\b",50 "hash_sha256": r"\b[a-f0-9]{64}\b",51}5253def extract_iocs(text: str) -> dict:54 return {k: re.findall(v, text) for k, v in IOC_PATTERNS.items()}55```56571. **Plan Operations** — Define objectives, scope, and success criteria for subdomain enumeration operations.582. **Prepare Environment** — Set up tools, access, and data sources required for subdomain enumeration.593. **Execute Core Workflow** — Use subfinder to perform subdomain enumeration operations following established procedures.604. **Validate Results** — Verify that results meet quality standards and objectives.615. **Report Findings** — Document results, observations, and recommendations.626. **Follow Up** — Track remediation actions and verify fixes where applicable.6364## Tools6566- **subfinder** — Primary tool for this skill67- **Analysis Platform** — Data processing and visualization68- **Collaboration Tools** — Team coordination and knowledge sharing697071## Process72731. **Design** — Define interface, identify patterns, plan implementation741. **Implement** — Write code following existing conventions, add tests751. **Verify** — Run tests, check integration, validate behavior7677## Verification7879- [ ] All subdomain enumeration procedures executed completely and documented80- [ ] Findings validated against multiple data sources81- [ ] False positives identified and filtered82- [ ] Results documented with evidence and timestamps83- [ ] Recommendations provided with risk-based prioritization8485## Anti-Rationalization Table8687| Rationalization | Reality |88|---|---|89| "We are too small to be targeted" | Automated attacks target everyone. Size does not matter. |90| "Security slows us down" | A breach slows you down 100x more. Build security in from the start. |91| "We will fix it after launch" | Vulnerabilities in production are exploited within hours. Fix before deploy. |