Ultimate Assetfinder Cheat Sheet
Ultimate Assetfinder Cheat Sheet
Find domains and subdomains related to a target. Passive reconnaissance at its finest.
1. Basic Usage
Find subdomains and related domains using passive sources.
Single Domain
With Subdomains Only
Returns only subdomains, filtering out the main domain.
Quiet Mode (No Banner)
Multiple Domains
Basic Flags
--subs-only: Subdomains only-q: Quiet mode-h: Help menu--version: Version info
Quick Examples
assetfinder tesla.comassetfinder --subs-only google.comassetfinder -q microsoft.comassetfinder apple.com amazon.com
2. Data Sources
Assetfinder queries multiple public sources to discover subdomains.
All Sources (Default)
Specific Sources
| Source | Description | Requires API Key? |
|---|---|---|
crtsh | Certificate Transparency logs | No |
certspotter | Cert Spotter API | No |
hackertarget | HackerTarget API | No |
threatcrowd | ThreatCrowd API | No |
virustotal | VirusTotal API | Yes |
facebook | Facebook CT logs | Yes |
spf | SPF records | No |
dns | DNS enumeration | No |
Some sources require API keys. Set them as environment variables:
export VIRUSTOTAL_API_KEY="your-key"export FACEBOOK_APP_ID="your-app-id"export FACEBOOK_APP_SECRET="your-app-secret"
3. Output & Filtering
Save to File
Sort and Remove Duplicates
Filter Live Domains
Pipe to httprobe to check which subdomains are live.
Get Only Root Domains
Extract IP Addresses
Useful Filters
sort -u: Sort and deduplicategrep -v: Exclude patternshttprobe: Check live hostsdnsx: DNS resolution
Output Processing
wc -l: Count resultstee file.txt: Save and displayawk -F. '{print $1}': Extract first partsed 's/\.$//': Remove trailing dots
4. Recon Pipeline
Combine Assetfinder with other tools for comprehensive reconnaissance.
Full Recon Pipeline
With Screenshots
With DNS Resolution
With Nmap Scanning
With Nuclei
Create a shell script for automated recon:
#!/bin/bash
assetfinder $1 | sort -u | httprobe | nuclei -t ~/nuclei-templates/ | notify
This discovers subdomains, checks live hosts, scans for vulnerabilities, and sends notifications.
5. Advanced Usage
Combine Multiple Sources
Filter Specific Subdomains
Find Specific Patterns
Exclude Wildcards
Combine with Other Tools
Combination Tools
subfinder: Another subdomain finderamass: OWASP recon toolfindomain: Fast subdomain finderchaos: ProjectDiscovery tool
Processing Tools
httpx: HTTP probehttprobe: Simple HTTP probednsx: DNS toolkitnuclei: Vulnerability scanner
6. Automation Scripts
Basic Recon Script
Continuous Monitoring
Multi-Domain Recon
1. Always use --subs-only for cleaner results
2. Sort and deduplicate with sort -u
3. Verify with httprobe or httpx
4. Schedule scans with cron
5. Use notify for alerts on new findings

Post a Comment