アップデート一覧に戻る
UpdatedAug 28, 2026

vegadns — Updated!

RustベースのDNS列挙およびサブドメイン発見ツールで、偵察やペネトレーションテストなどのセキュリティ評価に使用します。

共有

vegadns - subdomain enum and path discovery

license gitlab

vegadns

High-concurrency subdomain enum, passive OSINT, HTTP path discovery, and Java / hidden endpoint extract in one Rust binary.

Sanskrit vega = impetus / velocity. Also the star.

The problem this solves

Subdomain and content-discovery tools split into two camps: slow-but-clean passive OSINT and fast-but-junk-prone DNS brute. vegadns does both in one binary, and it filters the noise (wildcard DNS, soft-404s) that buries massdns and gobuster users in false positives. It is built and benchmarked against massdns, puredns, dnsx, subfinder, altdns, and ZDNS on planted-answer lab suites (see below).

Quick start

git clone [email protected]:WattoCyber/vegadns.git
cd vegadns
cargo build --release
./target/release/vegadns --help

Requires Rust stable. Full CLI reference in the README below or --help.

The shipped product is vegadns from src/ (cargo build --release). There is no Python on the scan path. scripts/*.py are optional peer-bench drivers (massdns / ffuf / subfinder H2H on the same mock) and are excluded from language statistics - see scripts/README.md.

LaneCommandWhat it does
Offlinewordlist / expand / permuteDepth packs, FQDN expand, altdns-class mutate (no network)
Lab DNSmock-serveFixture zone over UDP for peer H2H
Passive OSINTpassivePublic CT / datasets / APIs → in-scope names (no DNS brute)
DNSenumWordlist expand → concurrent UDP resolve → wildcard filter → emit
Live HTTPprobeHost list → concurrent GET → live URLs (httpx-class)
ArchivesharvestWayback CDX → in-scope hosts + subdirectory prefixes
SurfacemapPassive → recurse/permute → resolve → harvest → probe
HTTP pathspathsConcurrent path scan + soft-404 fingerprint filter
EndpointsendpointsJava / source / hidden seed + HTML/JS/robots/sitemap extract

Research pass covered massdns, puredns/shuffledns, dnsx, subfinder, alterx/gotator/altdns, and ZDNS. See docs/RESEARCH.md.

How to read the numbers

We plant a fixed set of real answers (oracle). Every tool gets the same wordlist and the same mock server.

ColumnPlain English
TimeSeconds until the tool finishes (lower is faster)
Real foundHow many planted answers it recovered (higher is better; max = oracle size)
ReportedHow many names/URLs it printed as hits
JunkReported − Real found (noise you still have to triage)
Clean hit rateReal found / Reported. 100% means every printed hit was real

Faster is not always better. A tool can finish first and still bury you in junk. We care about all real answers, almost no junk, then speed.

These are private lab / gym suites plus one public OSINT domain (hackerone.com). Not “fastest on the public internet.” Full raw tables: docs/BENCHMARKS.md. This-revision vegadns-only clocks: docs/feature_timing_cloud.json (python scripts/feature_timing.py).

Benchmarks at a glance

1. DNS lab - find subdomains, ignore wildcard noise

Setup: 500 real subdomains planted. Zone also answers random junk labels (wildcard). Wordlist: 8000 labels. Host: Kali.

toolTimeReal found (of 500)ReportedJunkClean hit rate
vegadns0.18s5005000100%
massdns0.43s50072122169%
gobuster-dns161s000-

Takeaway: vegadns and massdns both found every real name. massdns also printed 221 wildcard lies. vegadns filtered those and finished faster on this suite.

2. DNS stress gym - flaky resolver (latency + packet loss)

Setup: 800 real names. Mock DNS adds 10 ms delay, 5% SERVFAIL, 2% drop. Wordlist: 2000. Host: Kali.

toolTimeReal found (of 800)ReportedJunkClean hit rate
vegadns0.14s8008000100%
massdns0.55s8001700~90047%

Takeaway: vegadns wins wall and clean output on this suite. massdns still dumps ~half junk.

3. Same tool, before vs after hot-path work

Setup: Windows gym-stress, 3000 candidates, same 800 oracle. No peer race. We only compare vegadns to itself.

buildTimeReal foundClean hit rateNames checked / sec
before0.59s800 / 800100%5,047
after (best)0.40s800 / 800100%7,583

Takeaway: ~33% faster, ~50% more names per second, still zero junk. Detail: docs/OPTIMIZATION_BREAKTHROUGHS.md. Later ceiling work (UDP buffers, poll instead of spin, no silent concurrency clamps) is in docs/OPTIMIZATION_CEILING.md.

4. HTTP paths - server lies with “200 OK” on missing pages

Setup: 24 real paths planted (/admin, /api, …). Soft-404: missing paths still return HTTP 200 with a fixed “not found” body. Status-only tools treat those as hits. Wordlist mixes real paths + bait. Same process-wall clock for every tool.

toolTimeReal found (of 24)ReportedJunkClean hit rate
vegadns paths0.032s24240100%
feroxbuster1.03s24613739%

What this means

  1. Every timed tool found all 24 real paths.
  2. ferox also reported 37 fake pages (soft-404 200s).
  3. vegadns fingerprints the lie, drops fakes, prints exactly the 24 real URLs, and finishes faster.

Takeaway: vegadns wins clean output and wall on this fixed Kali suite (body drain + keep-alive reuse; process-wall H2H).

5. Same suites, re-run on Linux cloud host (2026-08-20)

Real adjacent binaries on PATH (massdns, dnsx, puredns, shuffledns, gobuster, ffuf, ferox). Single measured run. Full tables: docs/PEER_BENCH_CLOUD_2026-08-20.md.

DNS gym-stress (800 planted, 2000 labels, 10 ms / 5% SERVFAIL / 2% drop):

toolTimevs vegadnsReal found (of 800)JunkClean hit rateF1
vegadns0.164s1.0×8000100%1.000
massdns0.515s3.1×80090047%0.640
puredns1.211s7.4×80090047%0.640
shuffledns1.435s8.7×80090047%0.640
dnsx6.673s41×79589547%0.639

DNS lab (500 planted, 5000 labels, wildcard zone): vegadns 0.029s / 500/500 / 0 junk vs massdns 0.337s (11.8×, 400 junk) vs dnsx 0.502s (17.5×, 400 junk).

HTTP hard (24 planted, soft-404 200s; process-wall H2H vs peers):

toolTimeReal found (of 24)ReportedJunkClean hit rateF1
ffuf0.132s24603640%0.571
vegadns paths0.239s24240100%1.000
gobuster-dir0.461s23230100%0.979
feroxbuster0.777s24613739%0.565

カテゴリ