FIERCE
Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.
OVERVIEW#
Fierce is a DNS reconnaissance tool for locating non-contiguous IP space. It's used to find targets for penetration testing by enumerating DNS records.
BASIC USAGE#
fierce --domain example.com # Basic domain scan fierce -dns example.com # Alternative syntax
COMMON OPTIONS#
fierce --domain example.com --subdomains # Subdomain enumeration fierce --domain example.com --connect # Attempt HTTP connection fierce --domain example.com --wide # Scan entire class C ranges fierce --domain example.com --traverse 10 # Check nearby IPs (±10) fierce --domain example.com --search list.txt # Custom subdomain list fierce --domain example.com --range 10.0.0.0/24 # Scan specific range fierce --domain example.com --delay 3 # Delay between queries (seconds)
DNS SERVER OPTIONS#
fierce --domain example.com --dns-servers 8.8.8.8 fierce --domain example.com --dns-servers 8.8.8.8,1.1.1.1 fierce --domain example.com --dns-file servers.txt
OUTPUT OPTIONS#
fierce --domain example.com --file output.txt # Save results to file
SUBDOMAIN WORDLISTS#
# Default wordlist location (Kali) /usr/share/fierce/hosts.txt # Custom wordlist fierce --domain example.com --subdomain-file wordlist.txt
PRACTICAL EXAMPLES#
# Full reconnaissance scan fierce --domain target.com --wide --traverse 5 # Quick scan with custom DNS fierce --domain target.com --dns-servers 8.8.8.8 # Thorough subdomain enumeration fierce --domain target.com --subdomains --subdomain-file /usr/share/seclists/Discovery/DNS/subdomains-top1million-5000.txt # Zone transfer attempt fierce --domain target.com --traverse 0 # Scan with connection testing fierce --domain target.com --connect --wide
FIERCE OUTPUT INTERPRETATION#
Found: target.com (192.168.1.1) # Resolved hostname Nearby: 192.168.1.2 # Nearby IP found Zone: target.com # Zone information
TIPS#
- Start with basic scan, then expand - Use --traverse for adjacent IP discovery - Combine with other tools (nmap, nikto) for full recon - Check for zone transfers first - Use multiple DNS servers for better results
ALTERNATIVES#
dnsenum # DNS enumeration dnsrecon # DNS reconnaissance sublist3r # Subdomain enumeration amass # Attack surface mapping
INTEGRATION WITH OTHER TOOLS#
# Fierce to Nmap pipeline
fierce --domain target.com | grep -oE "\b([0-9]{1,3}\.){3}[0-9]{1,3}\b" | sort -u > ips.txt
nmap -iL ips.txt -sV -oN scan.txt