Skip to content
← LibraryTechnique entry
W-RECON-SUBDOMAINReconnaissance

Subdomain Enumeration

Enumerate subdomains via CT logs (crt.sh), passive DNS, subfinder/amass. Expands the attack surface for forgotten apps.

§ Where this technique fits

W-RECON-SUBDOMAIN is catalogued under the Reconnaissance tactic of the offensive-security kill-chain. It appears in 3 approved dossiers in the registry, typically at step 2 on average.

§ Dossiers chaining this technique

§ What commonly comes next

  1. 01
    Directory & File Bruteforce
    W-RECON-DIRBRUTE · Reconnaissance
    seen 1×
  2. 02
    Subdomain Takeover
    W-SUBDOMAIN-TAKEOVER · Initial Access
    seen 1×
  3. 03
    Tech Stack Fingerprinting
    W-RECON-FINGERPRINT · Reconnaissance
    seen 1×