Skip to content
KitploitKITPLOIT
FerramentasBlog
Enviar
FerramentasBlog
Enviar

Ferramentas de Hacking, PenTest e Cibersegurança para o seu Arsenal de Segurança!

Kitploit é um diretório de ferramentas de hacking, cibersegurança e pentesting. Descubra as últimas atualizações de projetos para encontrar vulnerabilidades, analisar sistemas, automatizar testes e fortalecer sua segurança.

··Feeds·Contato·Privacidade·© 2026 Kitploit

Diretório de Ferramentas

Categorias

Ver todas as categorias
Loading categories
Ferramentas/GitHubGitHub/xcapri/subdosec
ReconhecimentoScanners de VulnerabilidadesColeta de InformaçõesSegurança WebEnumeração de Subdomínios
GitHubxcapri/subdosec

subdosec

Escaneador rápido e preciso de takeover de subdomínios com zero falsos positivos. Detecta subdomínios vulneráveis, coleta metadados (IP, CNAME, título, código de status) e fornece análise assistida por IA para reconhecimento.

Ver Repositório
6421há 2 mesesRevisado pelo Kitploit

Mais Populares

Ver todos →

Descubra as ferramentas mais usadas pela nossa comunidade.

Explore todas as ferramentas

Navegue pela nossa coleção de ferramentas

Ver todas as ferramentas →
Compartilhar
subdosec — Escaneador rápido e preciso de takeover de subdomínios com zero falsos positivos. Detecta subdomínios vulneráveis, coleta metadados (IP, CNAME, título, código de status) e fornece análise assistida por IA para reconhecimento. | Kitploit
Site

Subdosec

Scanner de takeover de subdomínios & ferramenta de reconhecimento.


Demo

Instalação • Uso • Baseado na Web • Contribuição • Scanner Online • Agradecimentos


Subdosec é um scanner de takeover de subdomínios rápido e preciso, sem falsos positivos, com uma base de dados pública de subdomínios vulneráveis e metadados detalhados de não-vulneráveis (IP, CNAME, título e código de status) para reconhecimento.

Instalação

Instalar ou atualizar subdosec

root@kitploit:~
pipx install git+https://github.com/xcapri/subdosec.git
root@kitploit:~
pipx upgrade subdosec

Em seguida, execute isto sempre que iniciar uma nova sessão de terminal (até “server started successfully”).

root@kitploit:~
$ subdosec -ins

Starting Node.js server...
Node.js server started successfully.

Executando subdosec

[AVISO] Não tome takeover de todos os subdomínios em test.txt, deixe todos usarem isso para demonstrações.

[INFO] Consulte também a seção Release. Pode encontrar informações interessantes.

root@kitploit:~
$ subdosec -h
Expandir todas as flags de ajuda
root@kitploit:~
   _____       __        __
  / ___/__  __/ /_  ____/ /___  ________  _____
  \__ \/ / / / __ \/ __  / __ \/ ___/ _ \/ ___/
 ___/ / /_/ / /_/ / /_/ / /_/ (__  )  __/ /__
/____/\__,_/_.___/\__,_/\____/____/\___/\___/



usage: subdosec [-h] [-mode {private,public}] [-initkey INITKEY] [-vo] [-pe] [-ins] [-pf PF] [-subfng SUBFNG] [-lf LF] [-sfid] [-ks] [-o O] [-su] [-lu LU] [-lm] [-uf] [-unai UNAI] [-v] [-t THREADS]

Subdomain takeover scanner.

options:
  -h, --help            show this help message and exit
  -mode {private,public}
                        Mode of operation (private/public)
  -initkey INITKEY      Initialize the API key
  -vo                   VULN Only: Hide UNDETECT messages
  -pe                   Print Error: When there are problems detecting your target
  -ins                  Prepar node & start server
  -pf PF                Private Fingerprint: uses your local fingerprint. Example: -pf /path/to/tko.json
  -subfng SUBFNG        Submit fingerprint: submit local fingerprint to admin. Example: -subfng localfinger.json
  -lf LF                Fingerprint lock: to focus on one or multiple fingerprints. (-lf github.io,surge.sh) and leave this arg to scan all fingerprints
  -sfid                 To view all available fingerprint ids.
  -ks                   To shut down the server node if you want to not use subdosec for a long time.
  -o O                  Save result locally to the specified path. Example: -o /path/to/dir
  -su                   Skip undetect will not stored to server (https://subdosec.vulnshot.com/result/undetected)
  -lu LU                Undetec stored localy to the specified path. Example: -lu /path/to/dir
  -lm                   Local Mode: Save vuln and undetect to default inside tools directory (auto -su)
  -uf                   Update Fingerprint
  -unai UNAI            Analyze undetected subdomains using AI. Example: -unai /path/to/undetect.json
  -v, --verbose         Show progress count (e.g. [1/10])
  -t THREADS, --threads THREADS
                        Number of threads to use for scanning (default: 10)

Comandos Básicos

Preparar lista

Suporta sem protocolo

root@kitploit:~
cat list 

https://careers.rotacloud.com
http://creators.thinkorion.com
https://docs.polygon-nightfall.technology
a.anchorsawaytpt.com
help.oceges.com

CMD 1

Ignorar armazenamento de não detetados no servidor e salvar localmente

root@kitploit:~
cat test.txt | subdosec -lm

https://subdosec.vulnshot.com [UNDETECT]
http://feedback.bazoom.com [sleekplan.com] [VULN] [SAVED]
http://demodev.destinojet.co [meteor.com] [VULN] [SAVED]
http://creators.thinkorion.com [UNDETECT]
https://www.www.savillerow.status.lnt.cl [ohdear.app] [VULN] [SAVED]
https://careers.rotacloud.com [gohire.io] [VULN] [SAVED]
https://careers.rotacloud.com [gohire.io] [VULN] [SAVED]
https://ai.yooture.com [UNDETECT]
https://help.oceges.com [UNDETECT]
http://ftp.thiagolima.com [surge.sh] [VULN] [SAVED]


VULN DIRECTORY  : /home/alice/.subdosec/vulns
UNDETECT FILE   : /home/alice/.subdosec/undetect/undetect.json

Ler saída

root@kitploit:~
~$ ls /home/alice/.subdosec/vulns
gohire.io_tko.txt  meteor.com_tko.txt  ohdear.app_tko.txt  sleekplan.com_tko.txt  surge.sh_tko.txt
~$ cat /home/alice/.subdosec/vulns/gohire.io_tko.txt
careers.rotacloud.com

Ler undetect & analisar automaticamente novas potenciais vulnerabilidades com -unai

root@kitploit:~
cat /home/alice/.subdosec/undetect/undetect.json
[
    {
        "title": "No title found",
        "status_code": 404,
        "redirect_url": "No redirects",
        "cname_records": [
            "cname.redacted.com"
        ],
        "a_records": [
            "76.76.21.98",
            "76.76.21.241"
        ],
        "subdomain": "try.redacted.com",
        "rootdomain": "redacted.com"
    },
    {
        "title": "No title found",
        "status_code": 200,
        "redirect_url": "No redirects",
        "cname_records": [
            "cname.fermat.shop"
        ],
        "a_records": [
            "216.150.16.129",
            "216.150.1.129"
        ],
        "subdomain": "get.redacted.com",
        "rootdomain": "redacted.com"
    }
]
root@kitploit:~
subdosec -unai /home/pd/.subdosec/undetect/undetect.json

[INFO] PURE UNDETECTED 0 | Subdomains are not detected as vulnerable even though they have passed the subdosec scan..

[INFO] Analyzing 8 items in 2 batches.

[INFO] Progress: 5/8 data analyzed.

NEW POTENTIAL :


Domain     : try.redacted.com
  CNAME    : cname.redacted-service.com
  A Record : 76.76.21.98, 76.76.21.241
  Takeover : NOT
  Reason   : The redacted-service custom domain setup guide explicitly states the requirement of adding a TXT record (e.g., 'redacted-service-verification=<your_site_id>') for domain ownership verification. The presence of a TXT record verification step makes it not vulnerable.
  Reference: https://www.redacted-service.com/blog/how-to-setup-custom-domain/
================================================================================
Domain     : get.redacted.com
  CNAME    : cname.fermat.shop
  A Record : 216.150.16.129, 216.150.1.129
  Takeover : POSSIBLE
  Reason   : The service uses a static CNAME (cname.fermat.shop) for custom domain setup. Publicly available documentation for Fermat's custom domain setup does not clearly specify a requirement for a TXT record or any dynamic verification method for domain ownership. Without such verification, a static CNAME makes the subdomain potentially vulnerable if the corresponding Fermat account is deleted or becomes unlinked.
  Reference: https://fermat.shop/
================================================================================

CMD 2

Usar domínio raiz & ferramenta de descoberta de subdomínios em pipeline (ex: subfinder, assetfinder, amass, etc.)

root@kitploit:~
cat list
example.com 
root@kitploit:~
cat list | subfinder -silent | subdosec -lm

https://subdosec.vulnshot.com [UNDETECT]
http://feedback.bazoom.com [sleekplan.com] [VULN] [SAVED]
http://demodev.destinojet.co [meteor.com] [VULN] [SAVED]
http://creators.thinkorion.com [UNDETECT]
https://www.www.savillerow.status.lnt.cl [ohdear.app] [VULN] [SAVED]
https://careers.rotacloud.com [gohire.io] [VULN] [SAVED]
https://careers.rotacloud.com [gohire.io] [VULN] [SAVED]
https://ai.yooture.com [UNDETECT]
https://help.oceges.com [UNDETECT]
http://ftp.thiagolima.com [surge.sh] [VULN] [SAVED]


VULN DIRECTORY  : /home/alice/.subdosec/vulns
UNDETECT FILE   : /home/alice/.subdosec/undetect/undetect.json

CMD 3

(Encaminhar resultado para notify)

root@kitploit:~
cat list | subdosec -lm -vo | notify -silent 

https://careers.rotacloud.com [100.00%] [gohire.io] [VULN] [SAVED]

CMD 4

Usar impressão digital privada, esta flag irá automaticamente fundir impressão digital pública + privada

Expandir todas as flags de ajuda
root@kitploit:~
cat priv8.json

{
  "fingerprints": [
    {
      "fid": 0,
      "name": "Subdomain takeover - Pagedeck",
      "rules": {
        "cname": "cname.pagedeck.com",
        "status_code": "404",
"in_body":"This page could not be found."
      },
      "status_fingerprint": 0,
      "reference": "https://docs.pagedeck.com/getting-started/connecting-a-subdomain",
      "service": "pagedeck.com",
      "logo_service": "https://i.ytimg.com/vi/DY76Tjf1m-8/maxresdefault.jpg"
    },
    add more
]}
root@kitploit:~
 echo try.hugsleep.com | subdosec -pf privfinger.json  -o testpriv -lu okgaslu
   _____       __        __
  / ___/__  __/ /_  ____/ /___  ________  _____
  \__ \/ / / / __ \/ __  / __ \/ ___/ _ \/ ___/
 ___/ / /_/ / /_/ / /_/ / /_/ (__  )  __/ /__
/____/\__,_/_.___/\__,_/\____/____/\___/\___/



https://try.hugsleep.com [pagedeck.com] [VULN] [SAVED]


VULN DIRECTORY  : /home/pd/tko/testpriv
UNDETECT FILE   : /home/pd/tko/okgaslu/undetect.json

Baseado na Web

Conhecendo a função da web do subdosec, aqui pode usar a funcionalidade https://subdosec.vulnshot.com/result/undetected como reconhecimento, para descobrir IP, CNAME, TÍTULO, CÓDIGO DE STATUS, etc., como informação adicional ou até mesmo para encontrar novos takeover de subdomínios.

Tem a mesma função que undetect.json, a diferença é que você e outras pessoas partilham-no entre si.

Por exemplo, pesquisa um site que não é detetado como vulnerável pelo subdosec com a palavra-chave 404, e há informação sobre cname.gohire.io e o título GoHire, o que, se pesquisar no Google, não há artigo sobre takeover de subdomínio no serviço gohire.

Undetec

Contribuição

Depois de encontrar um novo takeover de subdomínio, manualmente ou automaticamente (usando -unai), pode submeter os dados para nós usando o comando subdosec -subfng.

Dinamicamente pode usar este elemento para as regras:

title, cname, status_code, in_body, a_record, redirect

root@kitploit:~
cat newvuln.json
{
  "name": "Subdomain takeover - GoHire",
  "rules": {
    "cname": "custom.gohire.io",
    "in_body": "Page not found",
    "status_code": "404"
  },
  "status_fingerprint": 0,
  "reference": "https://help.gohire.io/en/articles/3385288-setting-up-a-custom-domain",
  "service": "gohire.io",
  "logo_service": "https://gohire-website.s3.amazonaws.com/img/logos/gh-logo-main.gif"
}

root@kitploit:~
subdosec -subfng newvuln.json

[Info] Submitting fingerprint ...

Imported fingerprint data successfully

Scanner Online

Se não é uma pessoa com experiência em segurança, talvez um web-dev/programador e não está familiarizado com ferramentas CLI, pode usar a versão web para escanear todos os seus subdomínios com um máximo de 10 subdomínios por scan.

Undetec

Agradecimentos

As ferramentas antecessoras que inspiraram a criação das ferramentas subdosec.

  • can-i-take-over-xyz
  • can-i-take-over-dns
  • SubOver
  • subjack
  • nuclei-templates/http/takeovers
  • A comunidade de bug bounty pela inspiração e feedback.

subdosec é distribuído sob Licença MIT

Baixar ferramenta