← All cheat sheets

SUBFINDER

Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.

OVERVIEW#

Subfinder (ProjectDiscovery) is a fast passive subdomain enumeration
tool that queries many OSINT sources. It is built for pipelines -
output feeds directly into dnsx, httpx, naabu, and nuclei. Passive by
design, so low-noise recon. Authorized scope only.

BASIC USAGE#

subfinder -d corp.lu                          # Enumerate one domain
subfinder -d corp.lu -o subs.txt              # Save output
subfinder -dL domains.txt                     # Domains from a file
subfinder -d corp.lu -silent                  # Only results (pipe-friendly)
subfinder -d corp.lu -all                     # Use all sources (slower)

OUTPUT CONTROL#

subfinder -d corp.lu -silent                  # Clean list for pipes
subfinder -d corp.lu -oJ -o subs.json         # JSON lines output
subfinder -d corp.lu -oI                       # Include host IPs
subfinder -d corp.lu -cs                       # Show source per result
subfinder -d corp.lu -nc                       # No color

SOURCES / API KEYS#

subfinder -ls                                  # List all sources
subfinder -d corp.lu -sources crtsh,virustotal# Restrict to sources
subfinder -d corp.lu -es shodan               # Exclude a source
# API keys in $HOME/.config/subfinder/provider-config.yaml expand
# coverage (Censys, SecurityTrails, VirusTotal, GitHub, etc.)

PERFORMANCE#

subfinder -d corp.lu -t 50                     # Concurrency threads
subfinder -d corp.lu -timeout 30               # Per-source timeout
subfinder -d corp.lu -rl 10                     # Rate limit (req/s)
subfinder -d corp.lu -max-time 10              # Cap total minutes

PIPELINE (PROJECTDISCOVERY STACK)#

# subfinder -> dnsx (resolve) -> httpx (probe) -> naabu (ports) -> nuclei
subfinder -d corp.lu -silent | dnsx -silent | httpx -silent
subfinder -d corp.lu -silent | httpx -silent | nuclei -t cves/
subfinder -dL domains.txt -silent -o all-subs.txt

EXAMPLES#

# Quiet passive enumeration piped straight to live-host probing
subfinder -d corp.lu -silent | httpx -silent -title -status-code

# All-sources deep passive sweep to JSON
subfinder -d corp.lu -all -oJ -o subs.json

# Multi-domain scope with IP resolution
subfinder -dL scope.txt -oI -o subs-with-ips.txt

# Full triage chain: subs -> resolve -> probe -> scan
subfinder -d corp.lu -silent | dnsx -silent | httpx -silent | \
  nuclei -severity critical,high

NOTES#

- Passive only: subfinder does not brute force or resolve by default -
  pair with dnsx for resolution and Amass -brute for active discovery
- -silent is essential when piping into other tools
- Configure provider API keys for meaningfully larger result sets
- Complements AMASS (broader, graph-based) - run both and merge
- Fits a low-noise recon phase for TIBER-EU / DORA-scoped engagements
- Rust/Go-native, single binary - easy to pin in a NixOS toolchain