← Intel
Oct 5, 2026 · HackerOnStreet

Finding all Possible Subdomains Advance

Finding all Possible Subdomains Advance  #!/bin/bash # Replace 'example.com' with your target domain target_domain= "example.com" # Directory to store results output_dir= "/path/to/output_directory" # Ensure the output directory

finding possiblefinding possible subdomainsfindingpossiblesubdomainsadvanceenumdirsubdomainamassassetfindersublist3r

Quick overview

FieldDetail
Topicenum
GuideFinding all Possible Subdomains Advance
Tagsenum, output, dir, subdomains, subdomain, amass
LengthAbout 160 words
Practice ruleAuthorized labs only — stay ethical

Finding all Possible Subdomains Advance 



#!/bin/bash

# Replace 'example.com' with your target domain
target_domain="example.com"

# Directory to store results
output_dir="/path/to/output_directory"

# Ensure the output directory exists
mkdir -p "$output_dir"

# Enumerate subdomains using Amass, Sublist3r, and Assetfinder
amass_enum="$output_dir/amass_enum.txt"
sublist3r_enum="$output_dir/sublist3r_enum.txt"
assetfinder_enum="$output_dir/assetfinder_enum.txt"

amass enum -d $target_domain -o $amass_enum
sublist3r -d $target_domain -o $sublist3r_enum
assetfinder --subs-only $target_domain | tee $assetfinder_enum

# Combine the subdomain lists, remove duplicates, and sort
all_subdomains="$output_dir/all_subdomains.txt"
cat $amass_enum $sublist3r_enum $assetfinder_enum | sort -u > $all_subdomains

# Loop through the discovered subdomains and scan for open ports
while read -r subdomain; do
echo "Scanning subdomain: $subdomain"

# Use nmap to scan common ports on the subdomain
nmap -T4 -p 80,443,21,22,25 $subdomain -oA "$output_dir/$subdomain" > /dev/null

# You can add more ports or customize the nmap scan as needed
done < $all_subdomains

echo "Scan completed. Results saved in $output_dir"


Frequently asked questions

What is this guide about enum?

Finding all Possible Subdomains Advance explains practical, ethical notes on enum. Use it as a structured walkthrough — then practice only in authorized labs.

Who is this enum article for?

Readers who want clear, street-level guidance on enum without hype. Beginners and intermediate practitioners both benefit.

How do I practice enum safely?

Stay in scope: systems you own or have written permission to test. Keep notes, verify findings, and never attack live targets without authorization.