Ultimate Assetfinder Cheat Sheet



Ultimate Assetfinder Cheat Sheet

Find domains and subdomains related to a target. Passive reconnaissance at its finest.

1. Basic Usage

Find subdomains and related domains using passive sources.

Single Domain

assetfinder example.com

With Subdomains Only

assetfinder --subs-only example.com

Returns only subdomains, filtering out the main domain.

Quiet Mode (No Banner)

assetfinder -q example.com

Multiple Domains

assetfinder example.com example.org example.net

Basic Flags

  • --subs-only : Subdomains only
  • -q : Quiet mode
  • -h : Help menu
  • --version : Version info

Quick Examples

  • assetfinder tesla.com
  • assetfinder --subs-only google.com
  • assetfinder -q microsoft.com
  • assetfinder apple.com amazon.com

2. Data Sources

Assetfinder queries multiple public sources to discover subdomains.

All Sources (Default)

assetfinder example.com

Specific Sources

assetfinder --sources "crtsh,facebook,hackertarget" example.com
SourceDescriptionRequires API Key?
crtshCertificate Transparency logsNo
certspotterCert Spotter APINo
hackertargetHackerTarget APINo
threatcrowdThreatCrowd APINo
virustotalVirusTotal APIYes
facebookFacebook CT logsYes
spfSPF recordsNo
dnsDNS enumerationNo
Pro Tip: API Keys
Some sources require API keys. Set them as environment variables:
export VIRUSTOTAL_API_KEY="your-key"
export FACEBOOK_APP_ID="your-app-id"
export FACEBOOK_APP_SECRET="your-app-secret"

3. Output & Filtering

Save to File

assetfinder example.com > subdomains.txt

Sort and Remove Duplicates

assetfinder example.com | sort -u > unique-subdomains.txt

Filter Live Domains

assetfinder example.com | httprobe

Pipe to httprobe to check which subdomains are live.

Get Only Root Domains

assetfinder example.com | grep -v "^\*" | sort -u

Extract IP Addresses

assetfinder example.com | xargs -I{} host {} | grep "has address"

Useful Filters

  • sort -u : Sort and deduplicate
  • grep -v : Exclude patterns
  • httprobe : Check live hosts
  • dnsx : DNS resolution

Output Processing

  • wc -l : Count results
  • tee file.txt : Save and display
  • awk -F. '{print $1}' : Extract first part
  • sed 's/\.$//' : Remove trailing dots

4. Recon Pipeline

Combine Assetfinder with other tools for comprehensive reconnaissance.

Full Recon Pipeline

assetfinder example.com | sort -u | tee subs.txt | httprobe | tee live.txt

With Screenshots

assetfinder example.com | httprobe | gowitness file -f -

With DNS Resolution

assetfinder example.com | dnsx -resp -a -aaaa -cname

With Nmap Scanning

assetfinder example.com | httprobe | sed 's/https\?:\/\///' | xargs nmap -sV -sC

With Nuclei

assetfinder example.com | httprobe | nuclei -t /path/to/templates
Pro Tip: Complete Workflow

Create a shell script for automated recon:
#!/bin/bash
assetfinder $1 | sort -u | httprobe | nuclei -t ~/nuclei-templates/ | notify
This discovers subdomains, checks live hosts, scans for vulnerabilities, and sends notifications.

5. Advanced Usage

Combine Multiple Sources

assetfinder --sources "crtsh,certspotter,hackertarget,threatcrowd,dns" example.com

Filter Specific Subdomains

assetfinder example.com | grep -E "(dev|test|staging)"

Find Specific Patterns

assetfinder example.com | grep -E "(api|admin|portal|vpn)"

Exclude Wildcards

assetfinder example.com | grep -v "^\*\." | sort -u

Combine with Other Tools

cat <(assetfinder example.com) <(subfinder -d example.com) | sort -u

Combination Tools

  • subfinder : Another subdomain finder
  • amass : OWASP recon tool
  • findomain : Fast subdomain finder
  • chaos : ProjectDiscovery tool

Processing Tools

  • httpx : HTTP probe
  • httprobe : Simple HTTP probe
  • dnsx : DNS toolkit
  • nuclei : Vulnerability scanner

6. Automation Scripts

Basic Recon Script

#!/bin/bash # recon.sh - Automated subdomain enumeration DOMAIN=$1 OUTPUT_DIR="recon/$DOMAIN" mkdir -p $OUTPUT_DIR echo "[+] Running assetfinder..." assetfinder --subs-only $DOMAIN | sort -u > $OUTPUT_DIR/subs.txt echo "[+] Checking live hosts..." cat $OUTPUT_DIR/subs.txt | httprobe > $OUTPUT_DIR/live.txt echo "[+] Resolving DNS..." cat $OUTPUT_DIR/live.txt | dnsx -resp > $OUTPUT_DIR/resolved.txt echo "[+] Done! Results in $OUTPUT_DIR/"

Continuous Monitoring

#!/bin/bash # monitor.sh - Watch for new subdomains DOMAIN=$1 while true; do assetfinder --subs-only $DOMAIN | sort -u > /tmp/current.txt diff /tmp/previous.txt /tmp/current.txt | grep ">" | sed 's/> //' | notify mv /tmp/current.txt /tmp/previous.txt sleep 3600 done

Multi-Domain Recon

#!/bin/bash # multi-recon.sh - Recon on multiple domains for domain in $(cat domains.txt); do echo "[+] Scanning $domain..." assetfinder --subs-only $domain | sort -u > "recon_${domain}.txt" cat "recon_${domain}.txt" | httprobe > "live_${domain}.txt" echo "[+] Found $(wc -l < recon_${domain}.txt) subdomains" done
Pro Tip: Automation Best Practices

1. Always use --subs-only for cleaner results
2. Sort and deduplicate with sort -u
3. Verify with httprobe or httpx
4. Schedule scans with cron
5. Use notify for alerts on new findings

⇧