Do you miss AXFR technique? This tool allows to get the subdomains from a HTTPS website in a few seconds.
How it works? find-subdomains does not use neither dictionary attack nor brute-force, it just abuses of Certificate Transparency logs.
For more information about CT logs, check www.certificate-transparency.org and crt.sh.
Please, follow the instructions below for installing and run find-subdomains.
Make sure you have installed the following tools:
# Installing Node.js via package manager https://nodejs.org/en/download/package-manager/ # Installing Yarn (Node.js dependency management tools, Like python-pip) https://yarnpkg.com/en/docs/install # 1. Global install $ yarn global add find-subdomains # 1.1 Running $ find-subdomains github.com # Or # 2. Clone from GitHub $ git clone https://github.com/monkeym4ster/find-subdomains.git $ cd find-subdomains $ yarn install # 2.1 Running $ node find-subdomains.js github.com$ node find-subdomains.js- Sheila A. Berta - (@UnaPibaGeek).