Subdomain Enum
subdomain_enumDiscover subdomains for a domain via passive sources like CT logs, passive DNS, and scan archives, with optional source selection and scan-token chaining.
Instructions
Passive subdomain enumeration for a domain.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| domain | Yes | Root domain, e.g. "example.com". | |
| source | No | Which source(s) to query. Default "all" merges everything: certspotter (CT log), hackertarget (hostsearch), otx (AlienVault passive DNS), urlscan (scan archive), plus the local "subfinder" binary if installed. Any single name can be passed to use one source only. | all |
| from_token | No | Optional scan_token from an earlier call. |
Output Schema
| Name | Required | Description | Default |
|---|---|---|---|
| result | Yes |