#1Subdomain discovery, DNS brute-force, certificate transparency, and asset enumeration tools.
Kitploit recommended

An OSINT tool for collecting public information.

Rock-On is a all in one Recon tool that will just get a single entry of the Domain name and do all of the work alone.

Detects subdomain takeover vulnerabilities by analyzing DNS records and HTTP responses. Automatically identifies takeover-prone subdomains for…

Multi-threaded DNS-based enumeration tool for discovering AWS S3 buckets using pre-compiled wordlists and custom DNS resolvers, with optional Docker…

Striker is an offensive information and vulnerability scanner.

A Cloudflare resolver that works


Powerful Visual Subdomain Enumeration at the Click of a Mouse

Python 3.5+ DNS asynchronous brute force utility

A script to extract domain names from Content Security Policy(CSP) headers


Bash script that enumerates subdomains via Subfinder, resolves IPs, and identifies live web applications hosted on a domain for reconnaissance and…

Tool for checking Whether a domain or its multiple sub-domains are up and running.

Automated network asset, email, and social media profile discovery and cataloguing.

Automated reconnaissance wrapper — TomNomNom's meg on steroids. [DEPRECATED]

Dumain Bruteforcer - a fast and flexible domain bruteforcer

A Powerful Subdomain Takeover Tool

Some tools to automate recon - 003random