Oct 5, 2026 · HackerOnStreet
Finding all Possible Subdomains Advance
Finding all Possible Subdomains Advance #!/bin/bash # Replace 'example.com' with your target domain target_domain= "example.com" # Directory to store results output_dir= "/path/to/output_directory" # Ensure the output directory
finding possiblefinding possible subdomainsfindingpossiblesubdomainsadvanceenumdirsubdomainamassassetfindersublist3r
Quick overview
| Field | Detail |
|---|---|
| Topic | enum |
| Guide | Finding all Possible Subdomains Advance |
| Tags | enum, output, dir, subdomains, subdomain, amass |
| Length | About 160 words |
| Practice rule | Authorized labs only — stay ethical |
Finding all Possible Subdomains Advance
#!/bin/bash
# Replace 'example.com' with your target domain
target_domain="example.com"
# Directory to store results
output_dir="/path/to/output_directory"
# Ensure the output directory exists
mkdir -p "$output_dir"
# Enumerate subdomains using Amass, Sublist3r, and Assetfinder
amass_enum="$output_dir/amass_enum.txt"
sublist3r_enum="$output_dir/sublist3r_enum.txt"
assetfinder_enum="$output_dir/assetfinder_enum.txt"
amass enum -d $target_domain -o $amass_enum
sublist3r -d $target_domain -o $sublist3r_enum
assetfinder --subs-only $target_domain | tee $assetfinder_enum
# Combine the subdomain lists, remove duplicates, and sort
all_subdomains="$output_dir/all_subdomains.txt"
cat $amass_enum $sublist3r_enum $assetfinder_enum | sort -u > $all_subdomains
# Loop through the discovered subdomains and scan for open ports
while read -r subdomain; do
echo "Scanning subdomain: $subdomain"
# Use nmap to scan common ports on the subdomain
nmap -T4 -p 80,443,21,22,25 $subdomain -oA "$output_dir/$subdomain" > /dev/null
# You can add more ports or customize the nmap scan as needed
done < $all_subdomains
echo "Scan completed. Results saved in $output_dir"Frequently asked questions
What is this guide about enum?
Finding all Possible Subdomains Advance explains practical, ethical notes on enum. Use it as a structured walkthrough — then practice only in authorized labs.
Who is this enum article for?
Readers who want clear, street-level guidance on enum without hype. Beginners and intermediate practitioners both benefit.
How do I practice enum safely?
Stay in scope: systems you own or have written permission to test. Keep notes, verify findings, and never attack live targets without authorization.