SubDomainFinder

The SubDomainFinder by binsec.tools is a free tool for the systematic discovery of subdomains of a target domain. It helps security teams to identify hostnames and thereby make an organization’s external attack surface transparent. This allows potential entry points to be detected at an early stage, making SubDomainFinder a reliable foundation for penetration tests, red team exercises, and continuous security monitoring.

  • DNS brute-force (wordlist iteration): Systematically iterates through subdomain words against DNS to identify resolvable hostnames.
  • Certificate Transparency Logs (CT logs): Analysis of published TLS/SSL certificates for included Common Names and SAN entries that reveal subdomains.
  • Indexed search engine results (e.g., Google): Targeted search queries and analysis of indexed pages to identify subdomains mentioned in search results. The wordlists used can range from 500 to 50,000 words, depending on the desired duration.

All results are deduplicated and exported as a list, allowing the data to be directly integrated into subsequent processes such as port scanning, web path enumeration, or automated testing routines.

Limitations such as non-publicly visible internal hostnames or delays in CT logs affect only a small part of the relevant attack surface in practice and are rarely decisive in the initial analysis phases. For complete assessments, internal methods may be added; however, SubDomainFinder already provides a fast, extensive, and useful set of subdomains in most engagements. Legal requirements and a clearly defined scope remain important: with proper authorization and coordination, SubDomainFinder is an efficient, pragmatic tool for security researchers and penetration testers.

binsec academy GmbH – Advanced Pentest Training Lab

binsec academy GmbH operates the Pentest Training Lab, a highly practical online platform dedicated to real penetration testing. Simulating complex corporate networks and advanced real-world attack scenarios within isolated lab environments, it is engineered to sharpen the skills of aspiring and professional penetration testers. Upon conquering our rigorous, fully practical examination, participants earn the distinguished Binsec Academy Certified Pentest Professional (BACPP) designation — proving their technical capability to methodically uncover and evaluate vulnerabilities in modern IT infrastructures.

Explore the Pentest Training Lab

binsec GmbH – Experts in Penetration Testing

As the operative pentesting core of the binsec group, binsec GmbH has provided high-end, human-led penetration testing since 2013. Rejecting automated scans, our permanently employed, certified senior pentest experts deliver manual deep-dive assessments of web applications, APIs, mobile apps, complex network infrastructures, cloud environments, and advanced red team simulations. Specializing in high-regulation sectors like Payment, Banking, and Healthcare, we provide clear risk evaluations and actionable reports to effectively assess your business-critical systems.

Get Manual Expert Penetration Testing Services

Contact

binsec GmbH
Clemensstraße 6-8
60487 Frankfurt am Main
Germany

Legal notice

Director: Patrick Sauer
Authorized Officer: Dominik Sauer, Florian Zavatzki
Registration: Frankfurt am Main, HRB97277
Turnover Tax Identification No.: DE290966808