Subdomain Enumeration
semi-manual
cat domain-list | httprobe -s -p https:443
- gowitness
- takes a screenshot of a website and stores it on the filessytem
- automation
- https://github.com/thatonetester/sumrecon
- subjack for subdomain takeover
- waybackurls for scanning for wayback urls
tools
assetfinder
subfinder
OWASP amass
just google it
- google searches
- site:tesla -www -shop (for subdomain hunting)
- site:tesla.com -www -forms inurl:dev