#1Subdomain discovery, DNS brute-force, certificate transparency, and asset enumeration tools.
Kitploit recommended

Passive subdomain enumeration tool that extracts valid subdomains from certificate transparency logs using Python, ideal for reconnaissance and bug…
The Traditional Swiss Army Knife for OSINT

Automated reconnaissance framework integrating subdomain enumeration, live host probing, port scanning, CMS detection, and directory brute-forcing…

Information gathering tool - OSINT

HOCig- Automatic HOC Information Gathering Tool V 1.2

Windows-based reconnaissance tool combining subdomain enumeration, port scanning, banner grabbing, whois lookups, and web path enumeration for…

Multi Tool Subdomain Enumeration

An asynchronous enumeration & vulnerability scanner. Run all the tools on all the hosts.

The Offensive Manual Web Application Penetration Testing Framework.

Multithreaded Plugin based vulnerability scanner for mass detection of web-based applications vulnerabilities

BigBountyRecon tool utilises 58 different techniques using various Google dorks and open source tools to expedite the process of initial…

A tool that can help detect and takeover subdomains with dead DNS records

DNSProb is a tool built on top of retryabledns that allows you to perform multiple dns queries of your choice with a list of user supplied resolvers.

Subdomain Scan With Ping Method.

Web Application Security Automation Framework which recons the target for various assets to maximize the attack surface for security professionals &…

CVE-2020-13942 POC + Automation Script

Web-based project management interface for penetration testing and bug bounty workflows, automating port scanning with Nmap/Masscan and subdomain…