"Passive subdomain discovery from 40+ sources — Certificate Transparency, DNS records, and search engines."
The attack surface of an organization is almost always larger than anyone knows. Production subdomains, forgotten staging environments, internal tools accidentally exposed, old services left running — Subdomain Scanner finds them all using passive sources that require no active scanning of the target.
Subdomain Scanner queries 40+ passive intelligence sources simultaneously: Certificate Transparency logs (every SSL cert ever issued is public), DNS enumeration datasets, passive DNS databases, search engine indices, and OSINT telemetry. Because it's entirely passive, it's undetectable — no requests are sent to the target itself.
The optional recursive setting runs Subdomain Scanner on every discovered subdomain, revealing the full depth of the subdomain tree. This is essential for large organizations where api.internal.example.com might be more interesting than api.example.com.