SUBFINDER
Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.
OVERVIEW#
Subfinder (ProjectDiscovery) is a fast passive subdomain enumeration tool that queries many OSINT sources. It is built for pipelines - output feeds directly into dnsx, httpx, naabu, and nuclei. Passive by design, so low-noise recon. Authorized scope only.
BASIC USAGE#
subfinder -d corp.lu # Enumerate one domain subfinder -d corp.lu -o subs.txt # Save output subfinder -dL domains.txt # Domains from a file subfinder -d corp.lu -silent # Only results (pipe-friendly) subfinder -d corp.lu -all # Use all sources (slower)
OUTPUT CONTROL#
subfinder -d corp.lu -silent # Clean list for pipes subfinder -d corp.lu -oJ -o subs.json # JSON lines output subfinder -d corp.lu -oI # Include host IPs subfinder -d corp.lu -cs # Show source per result subfinder -d corp.lu -nc # No color
SOURCES / API KEYS#
subfinder -ls # List all sources subfinder -d corp.lu -sources crtsh,virustotal# Restrict to sources subfinder -d corp.lu -es shodan # Exclude a source # API keys in $HOME/.config/subfinder/provider-config.yaml expand # coverage (Censys, SecurityTrails, VirusTotal, GitHub, etc.)
PERFORMANCE#
subfinder -d corp.lu -t 50 # Concurrency threads subfinder -d corp.lu -timeout 30 # Per-source timeout subfinder -d corp.lu -rl 10 # Rate limit (req/s) subfinder -d corp.lu -max-time 10 # Cap total minutes
PIPELINE (PROJECTDISCOVERY STACK)#
# subfinder -> dnsx (resolve) -> httpx (probe) -> naabu (ports) -> nuclei subfinder -d corp.lu -silent | dnsx -silent | httpx -silent subfinder -d corp.lu -silent | httpx -silent | nuclei -t cves/ subfinder -dL domains.txt -silent -o all-subs.txt
EXAMPLES#
# Quiet passive enumeration piped straight to live-host probing subfinder -d corp.lu -silent | httpx -silent -title -status-code # All-sources deep passive sweep to JSON subfinder -d corp.lu -all -oJ -o subs.json # Multi-domain scope with IP resolution subfinder -dL scope.txt -oI -o subs-with-ips.txt # Full triage chain: subs -> resolve -> probe -> scan subfinder -d corp.lu -silent | dnsx -silent | httpx -silent | \ nuclei -severity critical,high
NOTES#
- Passive only: subfinder does not brute force or resolve by default - pair with dnsx for resolution and Amass -brute for active discovery - -silent is essential when piping into other tools - Configure provider API keys for meaningfully larger result sets - Complements AMASS (broader, graph-based) - run both and merge - Fits a low-noise recon phase for TIBER-EU / DORA-scoped engagements - Rust/Go-native, single binary - easy to pin in a NixOS toolchain