07/04/2026
π Advanced Subdomain Hunter β Automated Recon Framework
I built a Bash automation tool for passive subdomain enumeration to reconnaissance during pe*******on testing and bug bounty program.
π Overview
This tool automates multiple industry-standard OSINT enumeration utilities and consolidates their output into a single, clean, deduplicated result set.
attached tools:
ππ» Subfinder
ππ» OWASP Amass
ππ» Sublist3r
β
Passive Enumeration
Each tool runs in passive mode to avoid active probing:
Subfinder β Collects subdomains from multiple OSINT sources
Amass (Passive) β Gathers data from public intelligence datasets
Sublist3r β Extracts subdomains via search engine enumeration
This ensures safe reconnaissance aligned with responsible disclosure practices.
β
Reporting
The script automatically:
Counts total unique subdomains
Displays a clean summary
Provides the final output path
π― Key Features
β Multi-tool automation
β Passive reconnaissance only
β Regex-based validation
β Duplicate removal
β Structured output management
β Timestamp-based versioning