Skip to content
KitploitKITPLOIT
StrumentiExploitsBlog
Log in
Invia
StrumentiExploitsBlog
Invia

Strumenti di Hacking, PenTest e Cybersecurity per il tuo Arsenale di Sicurezza!

Kitploit è una directory di strumenti di hacking, cybersecurity e pentesting. Scopri gli ultimi aggiornamenti dei progetti per trovare vulnerabilità, analizzare sistemi, automatizzare i test e rafforzare la tua sicurezza.

FeedContattoPrivacy© 2026 Kitploit

Directory degli strumenti

Categorie

Vedi tutte le categorie
Loading categories
subfinder — Strumento veloce per l'enumerazione passiva dei sottodomini. | Kitploit
Strumenti/GitHubGitHub/projectdiscovery/subfinder
OSINT (Open Source Intelligence)RicognizioneOSINT per Ingegneria SocialeEnumerazione DNS e SottodominiScripting e AutomazioneRaccolta InformazioniPenetration TestingEnumerazione SottodominiRaccolta EmailFuzzing DNSRed Teaming
14.2k1.6k15511h 47m faRevisionato da Kitploit

Più Popolari

Vedi tutti →

Scopri gli strumenti più utilizzati dalla nostra community.

Esplora tutti gli strumenti

Sfoglia la nostra collezione di strumenti

Vedi tutti gli strumenti →
Condividi
Analisi DNS
Top in Analisi DNS n.7
Top in Fuzzing DNS n.18
Top in Enumerazione DNS e Sottodomini n.1
Top in Raccolta Email n.14
Top in Raccolta Informazioni n.4
Top in OSINT (Open Source Intelligence) n.14
Top in OSINT per Ingegneria Sociale n.15
Top in Penetration Testing n.10
Top in Ricognizione n.2
Top in Scripting e Automazione n.4
Top in Enumerazione Sottodomini n.1
GitHubprojectdiscovery/subfinder

subfinder

Strumento veloce per l'enumerazione passiva dei sottodomini.

Vedi RepositorySito web

subfinder

Strumento veloce per l'enumerazione passiva dei sottodomini.

Funzionalità • Installazione • Utilizzo • Configurazione API • Libreria • Unisciti a Discord


subfinder è uno strumento di scoperta di sottodomini che restituisce sottodomini validi per siti web, utilizzando fonti passive online. Ha un'architettura semplice e modulare ed è ottimizzato per la velocità. subfinder è progettato per fare una sola cosa - l'enumerazione passiva dei sottodomini - e la fa molto bene.

Lo abbiamo realizzato per rispettare tutte le licenze e le restrizioni d'uso delle fonti passive utilizzate. Il modello passivo garantisce velocità e furtività che possono essere sfruttate sia dai penetration tester che dai bug bounty hunter.

Funzionalità

subfinder

  • Moduli veloci e potenti per la risoluzione e l'eliminazione dei wildcard
  • Fonti passive curate per massimizzare i risultati
  • Molteplici formati di output supportati (JSON, file, stdout)
  • Ottimizzato per la velocità e leggero nell'uso delle risorse
  • Supporto STDIN/OUT che consente una facile integrazione nei workflow

Utilizzo

subfinder -h

Questo mostrerà l'aiuto per lo strumento. Di seguito sono elencate tutte le opzioni supportate.

Usage:
  ./subfinder [flags]

Flags:
INPUT:
  -d, -domain string[]  domains to find subdomains for
  -dL, -list string     file containing list of domains for subdomain discovery

SOURCE:
  -s, -sources string[]           specific sources to use for discovery (-s crtsh,github). Use -ls to display all available sources.
  -recursive                      use only sources that can handle subdomains recursively (e.g. subdomain.domain.tld vs domain.tld)
  -all                            use all sources for enumeration (slow)
  -es, -exclude-sources string[]  sources to exclude from enumeration (-es alienvault,zoomeyeapi)

FILTER:
  -m, -match string[]     subdomain or list of subdomain to match (file or comma separated)
  -f, -filter string[]     subdomain or list of subdomain to filter (file or comma separated)
  -match-regex string[]   regex or list of regex to match on output subdomain (cli, file)
  -filter-regex string[]  regex or list of regex to filter on output subdomain (cli, file)

RATE-LIMIT:
  -rl, -rate-limit int  maximum number of http requests to send per second
  -rls value            maximum number of http requests to send per second for providers in key=value format (-rls "hackertarget=10/s,shodan=15/s")
  -t int                number of concurrent goroutines for resolving (-active only) (default 10)

UPDATE:
  -up, -update                 update subfinder to latest version
  -duc, -disable-update-check  disable automatic subfinder update check

OUTPUT:
  -o, -output string       file to write output to
  -oJ, -json               write output in JSONL format
  -oD, -output-dir string  directory to write output (-dL only)
  -cs, -collect-sources    include all sources in the output (-json only)
  -oI, -ip                 include host IP in output (-active only)

CONFIGURATION:
  -config string                flag config file (default "$CONFIG/subfinder/config.yaml")
  -pc, -provider-config string  provider config file (default "$CONFIG/subfinder/provider-config.yaml")
  -r string[]                   comma separated list of resolvers to use
  -rL, -rlist string            file containing list of resolvers to use
  -nW, -active                  display active subdomains only
  -proxy string                 http proxy to use with subfinder
  -ei, -exclude-ip              exclude IPs from the list of domains
  -mr, -max-results int         limit the number of results per source (0 = unlimited; honored by paginating sources)

DEBUG:
  -silent             show only subdomains in output
  -version            show version of subfinder
  -v                  show verbose output
  -nc, -no-color      disable color in output
  -ls, -list-sources  list all available sources (-oJ for JSON)

OPTIMIZATION:
  -timeout int                  seconds to wait before timing out (default 30)
  -max-time int                 minutes to wait for enumeration results (default 10)
  -rsr, -response-size-read int max response body size to read in bytes from passive sources (0 = unlimited)

Variabili d'ambiente

Subfinder supporta variabili d'ambiente per specificare percorsi personalizzati per i file di configurazione:

  • SUBFINDER_CONFIG - Percorso del file config.yaml (sovrascrive il valore predefinito $CONFIG/subfinder/config.yaml)
  • SUBFINDER_PROVIDER_CONFIG - Percorso del file provider-config.yaml (sovrascrive il valore predefinito $CONFIG/subfinder/provider-config.yaml)

Installazione

subfinder richiede go1.26 per essere installato correttamente. Esegui il seguente comando per installare l'ultima versione:

go install -v github.com/projectdiscovery/subfinder/v2/cmd/subfinder@latest

Scopri altri modi per installare subfinder qui: https://docs.projectdiscovery.io/tools/subfinder/install.

Istruzioni post-installazione

subfinder può essere utilizzato subito dopo l'installazione, tuttavia molte fonti richiedono chiavi API per funzionare. Scopri di più qui: https://docs.projectdiscovery.io/tools/subfinder/install#post-install-configuration.

Esecuzione di Subfinder

Scopri come eseguire Subfinder qui: https://docs.projectdiscovery.io/tools/subfinder/running.

Filtrare i risultati con espressioni regolari

-match-regex e -filter-regex accettano espressioni regolari Go, ripetute o da un file (una per riga), e si combinano con -match e -filter:

subfinder -d example.com -match-regex '^(api|web)[0-9]{1,3}\.' -filter-regex '(^|\.)dev\.'

Libreria Go di Subfinder

Subfinder può anche essere utilizzato come libreria e un esempio minimale dell'uso dell'SDK di subfinder è disponibile qui

Risorse

  • Recon with Me !!!

Licenza

subfinder è realizzato con 🖤 dal team projectdiscovery. I contributi della community hanno reso il progetto ciò che è. Consulta il file THANKS.md per maggiori dettagli.

Leggi l'esclusione di responsabilità sull'utilizzo in DISCLAIMER.md e contattaci per qualsiasi rimozione di API.

Scarica lo strumento