
Rápida herramienta de enumeración pasiva de subdominios.
Características • Instalación • Uso • Configuración de API • Librería • Únete a Discord
subfinder es una herramienta de descubrimiento de subdominios que devuelve subdominios válidos para sitios web, utilizando fuentes pasivas en línea. Tiene una arquitectura simple y modular, y está optimizada para la velocidad. subfinder está diseñada para
hacer una sola cosa: enumeración pasiva de subdominios, y lo hace muy bien.
La hemos creado para cumplir con todas las licencias y restricciones de uso de las fuentes pasivas utilizadas. El modelo pasivo garantiza la velocidad y el sigilo que pueden aprovechar tanto los pentesters como los cazadores de bug bounty.
subfinder -h
Esto mostrará la ayuda de la herramienta. Aquí están todos los modificadores que soporta.
Usage:
./subfinder [flags]
Flags:
INPUT:
-d, -domain string[] domains to find subdomains for
-dL, -list string file containing list of domains for subdomain discovery
SOURCE:
-s, -sources string[] specific sources to use for discovery (-s crtsh,github). Use -ls to display all available sources.
-recursive use only sources that can handle subdomains recursively (e.g. subdomain.domain.tld vs domain.tld)
-all use all sources for enumeration (slow)
-es, -exclude-sources string[] sources to exclude from enumeration (-es alienvault,zoomeyeapi)
FILTER:
-m, -match string[] subdomain or list of subdomain to match (file or comma separated)
-f, -filter string[] subdomain or list of subdomain to filter (file or comma separated)
-match-regex string[] regex or list of regex to match on output subdomain (cli, file)
-filter-regex string[] regex or list of regex to filter on output subdomain (cli, file)
RATE-LIMIT:
-rl, -rate-limit int maximum number of http requests to send per second
-rls value maximum number of http requests to send per second for providers in key=value format (-rls "hackertarget=10/s,shodan=15/s")
-t int number of concurrent goroutines for resolving (-active only) (default 10)
UPDATE:
-up, -update update subfinder to latest version
-duc, -disable-update-check disable automatic subfinder update check
OUTPUT:
-o, -output string file to write output to
-oJ, -json write output in JSONL format
-oD, -output-dir string directory to write output (-dL only)
-cs, -collect-sources include all sources in the output (-json only)
-oI, -ip include host IP in output (-active only)
CONFIGURATION:
-config string flag config file (default "$CONFIG/subfinder/config.yaml")
-pc, -provider-config string provider config file (default "$CONFIG/subfinder/provider-config.yaml")
-r string[] comma separated list of resolvers to use
-rL, -rlist string file containing list of resolvers to use
-nW, -active display active subdomains only
-proxy string http proxy to use with subfinder
-ei, -exclude-ip exclude IPs from the list of domains
-mr, -max-results int limit the number of results per source (0 = unlimited; honored by paginating sources)
DEBUG:
-silent show only subdomains in output
-version show version of subfinder
-v show verbose output
-nc, -no-color disable color in output
-ls, -list-sources list all available sources (-oJ for JSON)
OPTIMIZATION:
-timeout int seconds to wait before timing out (default 30)
-max-time int minutes to wait for enumeration results (default 10)
-rsr, -response-size-read int max response body size to read in bytes from passive sources (0 = unlimited)
Subfinder soporta variables de entorno para especificar rutas personalizadas para los archivos de configuración:
SUBFINDER_CONFIG - Ruta al archivo config.yaml (sobrescribe el valor predeterminado $CONFIG/subfinder/config.yaml)SUBFINDER_PROVIDER_CONFIG - Ruta al archivo provider-config.yaml (sobrescribe el valor predeterminado $CONFIG/subfinder/provider-config.yaml)subfinder requiere go1.26 para instalarse correctamente. Ejecuta el siguiente comando para instalar la última versión:
go install -v github.com/projectdiscovery/subfinder/v2/cmd/subfinder@latest
Aprende más formas de instalar subfinder aquí: https://docs.projectdiscovery.io/tools/subfinder/install.
subfinder se puede usar justo después de la instalación, sin embargo, muchas fuentes requieren claves API para funcionar. Aprende más aquí: https://docs.projectdiscovery.io/tools/subfinder/install#post-install-configuration.
Aprende cómo ejecutar Subfinder aquí: https://docs.projectdiscovery.io/tools/subfinder/running.
-match-regex y -filter-regex aceptan expresiones regulares de Go, repetidas o desde un archivo (una por línea), y se combinan con -match y -filter:
subfinder -d example.com -match-regex '^(api|web)[0-9]{1,3}\.' -filter-regex '(^|\.)dev\.'
Subfinder también se puede usar como librería y hay un ejemplo mínimo del uso del SDK de subfinder disponible aquí
subfinder está hecho con 🖤 por el equipo de projectdiscovery. Las contribuciones de la comunidad han hecho del proyecto lo que es. Consulta
el archivo THANKS.md para más detalles.
Lee el aviso de uso en DISCLAIMER.md y contáctanos para cualquier eliminación de API.