← All cheat sheets

FIERCE

Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.

OVERVIEW#

Fierce is a DNS reconnaissance tool for locating non-contiguous IP space.
It's used to find targets for penetration testing by enumerating DNS records.

BASIC USAGE#

fierce --domain example.com               # Basic domain scan
fierce -dns example.com                   # Alternative syntax

COMMON OPTIONS#

fierce --domain example.com --subdomains  # Subdomain enumeration
fierce --domain example.com --connect     # Attempt HTTP connection
fierce --domain example.com --wide        # Scan entire class C ranges
fierce --domain example.com --traverse 10 # Check nearby IPs (±10)
fierce --domain example.com --search list.txt  # Custom subdomain list
fierce --domain example.com --range 10.0.0.0/24  # Scan specific range
fierce --domain example.com --delay 3     # Delay between queries (seconds)

DNS SERVER OPTIONS#

fierce --domain example.com --dns-servers 8.8.8.8
fierce --domain example.com --dns-servers 8.8.8.8,1.1.1.1
fierce --domain example.com --dns-file servers.txt

OUTPUT OPTIONS#

fierce --domain example.com --file output.txt   # Save results to file

SUBDOMAIN WORDLISTS#

# Default wordlist location (Kali)
/usr/share/fierce/hosts.txt

# Custom wordlist
fierce --domain example.com --subdomain-file wordlist.txt

PRACTICAL EXAMPLES#

# Full reconnaissance scan
fierce --domain target.com --wide --traverse 5

# Quick scan with custom DNS
fierce --domain target.com --dns-servers 8.8.8.8

# Thorough subdomain enumeration
fierce --domain target.com --subdomains --subdomain-file /usr/share/seclists/Discovery/DNS/subdomains-top1million-5000.txt

# Zone transfer attempt
fierce --domain target.com --traverse 0

# Scan with connection testing
fierce --domain target.com --connect --wide

FIERCE OUTPUT INTERPRETATION#

Found: target.com (192.168.1.1)     # Resolved hostname
Nearby: 192.168.1.2                 # Nearby IP found
Zone: target.com                    # Zone information

TIPS#

- Start with basic scan, then expand
- Use --traverse for adjacent IP discovery
- Combine with other tools (nmap, nikto) for full recon
- Check for zone transfers first
- Use multiple DNS servers for better results

ALTERNATIVES#

dnsenum                             # DNS enumeration
dnsrecon                            # DNS reconnaissance
sublist3r                           # Subdomain enumeration
amass                               # Attack surface mapping

INTEGRATION WITH OTHER TOOLS#

# Fierce to Nmap pipeline
fierce --domain target.com | grep -oE "\b([0-9]{1,3}\.){3}[0-9]{1,3}\b" | sort -u > ips.txt
nmap -iL ips.txt -sV -oN scan.txt