assetfinder
Fast subdomain discovery using passive sources. Simple and effective.
Quickstart
assetfinder target.com
assetfinder --subs-only target.com
assetfinder --subs-only target.com | httpx -silent
Core Concepts
| Concept |
Description |
| Passive |
Uses external data sources |
| Fast |
Simple and quick results |
| Sources |
crt.sh, certspotter, hackertarget, etc. |
Syntax
assetfinder [options] <domain>
Options
| Option |
Description |
--subs-only |
Only subdomains (not related) |
Recipes
Basic Usage
assetfinder target.com
assetfinder --subs-only target.com
assetfinder --subs-only target.com > subs.txt
Multiple Domains
for domain in $(cat domains.txt); do
assetfinder --subs-only $domain
done | sort -u
cat domains.txt | xargs -I {} assetfinder --subs-only {}
Pipeline Integration
assetfinder --subs-only target.com | httpx -silent
assetfinder --subs-only target.com | dnsx -silent
assetfinder --subs-only target.com | \
httpx -silent | \
nuclei -t cves/
(assetfinder --subs-only target.com; subfinder -d target.com -silent) | sort -u
Filtering Results
assetfinder --subs-only target.com | sort -u
assetfinder --subs-only target.com | wc -l
assetfinder --subs-only target.com | grep -E "^(dev|staging|test)\."
Output & Parsing
assetfinder --subs-only target.com > subs.txt
assetfinder --subs-only target.com | sort -u > subs.txt
assetfinder --subs-only target.com
Troubleshooting
| Issue |
Solution |
| No results |
Check domain, try different tool |
| Duplicates |
Pipe through sort -u |
| Too many results |
Use --subs-only |
References