Skip to content
KitploitKITPLOIT
工具漏洞利用博客
Log in
提交
工具漏洞利用博客
提交

黑客、渗透测试和网络安全工具,武装您的安全武器库!

Kitploit 是一个黑客、网络安全和渗透测试工具的目录。发现最新的项目更新,查找漏洞、分析系统、自动化测试并加强你的安全。

··订阅源·联系·隐私·© 2026 Kitploit

工具目录

分类

查看所有分类
Loading categories
Sububy — 模块化子域名枚举套件,支持证书透明度、DNS暴力破解和基于API的发现。包含枚举后模块,用于排序、存活主机检测、屏幕截图捕获和HTTP信息检索。 | Kitploit
工具/GitHubGitHub/a3h1nt/sububy
OSINT (开源情报)侦察DNS和子域名枚举信息收集子域名枚举
GitHuba3h1nt/sububy

Sububy

模块化子域名枚举套件,支持证书透明度、DNS暴力破解和基于API的发现。包含枚举后模块,用于排序、存活主机检测、屏幕截图捕获和HTTP信息检索。

查看仓库
71181年前尚未审核

最受欢迎

查看全部 →

发现我们社区最常用的工具。

探索所有工具

浏览我们的工具集合

查看所有工具 →
分享

Sububy

Sububy 是一款用 Ruby 编写的一站式子域名枚举套件,它专注于准确性与质量,并允许你单独调用部分模块而无需遵循工具的执行流程,从而能够将之集成到你的工作流中。

alt text

Sububy 总共包含九个模块,其中六个用于枚举,其余执行枚举后操作。

类别模块描述
枚举Cert从证书透明度日志中检索子域名。
Brute使用提供的字典暴力枚举子域名。
Dnsd从 DnsDumpster 获取子域名(需要 API 密钥:免费)。
Vtotal从 VirusTotal 获取子域名(需要 API 密钥:免费)。
WebArch从互联网网页档案馆获取子域名
Csp从已发现存活域名的 CSP 中获取子域名。
后枚举Sort对已发现的子域名进行排序,去除重复项以及不属于目标域名的主机。
Live识别运行有活跃网页服务器的子域名。
Sshot使用 HTTP 和 HTTPS 协议截取屏幕截图。
Info允许你检索基本 HTTP 信息,如响应状态码和响应头。

安装

  1. 安装工具及依赖的 gem
git clone https://github.com/A3h1nt/Sububy.git
cd Sububy
bundle install 
  1. 在 Sububy.rb 中配置 API 密钥,可通过以下 URL 获取:
  • DnsDumpster
  • VirusTotal
  1. 运行
ruby Sububy.rb <domain> <cn> <wordlist> <output-dir>

alt text

单独调用模块

Sububy 的模块设计允许你单独调用,无需反复运行整个工具。在开始使用单个模块之前,你需要先在 Ruby shell 中加载文件。在终端输入 irb 启动 Ruby shell,然后加载 sububy 文件。

irb(main):002:0> require_relative 'Sububy.rb'
irb(main):002:0> # Set the output directory
irb(main):002:0> $output_dir = '/path/to/output_dir'

1. 枚举模块

只想枚举子域名?

Cert.get(domain) #-> cert.txt
Brute.bruteforce(domain,wordlist) #-> brute.txt
Dnsd.getsub(domain) #-> dnsd.txt
Vtotal.getsub(domain) #-> vtotal.txt
WebArch.get(domain) #-> webarchive.txt

2. 排序模块

已经有一个子域名列表,需要排序?

Sort.domain(domain,file) #-> returns identified_host.txt with domain name mentioned in subdomain
Sort.uniq(file1,file2) #-> combine and returns unique subdomains 

3. 存活模块

已经有一个子域名列表,需要找出存活的?

Live.get(host_file) #-> returns live_host.txt with list of alive host

4. 截图模块

已经有一个子域名列表,想要截取屏幕截图?

Sshot.http(host_file) #-> returns http screenshots in http/
Sshot.https(host_file) #-> returns https screenshoots in https/

5. 信息模块

想获取关于子域名的更多信息?

Info.info "hosts.txt" #-> Initiates the info module, you need to run this before you can use other methods
Info.headers "hostname" #-> Returns response headers for a particular host
Info.headersall #-> Returns response headers for all hosts specified in the file
Info.status "hostname" #-> Returns response status code for a particular host
Info.statusall #-> Returns response status for all hosts specified in the file
Info.title "hostname" #-> Returns webpage title for a particular host
Info.titleall #-> Returns webpage title for all hosts specified in the file
Info.comments #-> Writes scaraped comments to file
Info.links #-> Writes scraped links to file

变量

Sububy 使用一些全局变量来存储数据,这些变量也可以直接访问。

$dnsdumpster_api_key  # API key for dnsdumpster
$virustotal_api_key   # API key for virustotal
$live_host            # Array of live host
$csp_list = []        # Array of host identified from CSP
$output_dir           # Path to output directory

如何贡献?

  • 添加新功能
  • 改进代码质量
  • 解决错误

联系我:[email protected]

下载工具