offensive-tools/recon/sublist3r/SKILL.md
Subdomain enumeration using OSINT sources (Google, Bing, Baidu, DNSDumpster, VirusTotal, ThreatCrowd). Use when passively enumerating subdomains from public search engines and threat intel platforms.
npx skillsauth add aeondave/malskill sublist3rInstall this skill globally with one command. Works with Claude Code, Cursor, and Windsurf.
3 of 9 scanners reported clean
Some scanners were skipped, did not run, or reported a non-clean status. Review each row below.
Passive subdomain enumeration via OSINT — search engines, DNSDumpster, VirusTotal.
pip install sublist3r
# Basic subdomain enum
sublist3r -d target.com
# With brute-force
sublist3r -d target.com -b -w wordlist.txt
# Save output
sublist3r -d target.com -o subdomains.txt
# Verbose (show sources)
sublist3r -d target.com -v
| Flag | Purpose |
|------|---------|
| -d DOMAIN | Target domain |
| -b | Enable brute-force |
| -w FILE | Brute-force wordlist |
| -p PORTS | Check ports on found hosts |
| -v | Verbose (show each source) |
| -t N | Threads (default: 10) |
| -o FILE | Output file |
| -e ENGINES | Comma-separated engines |
Google · Bing · Yahoo · Baidu · Ask · Netcraft · DNSDumpster · VirusTotal · ThreatCrowd · SSL certs · PassiveDNS
Passive only (stealthy):
sublist3r -d target.com -o passive_subs.txt
Active brute + passive combined:
sublist3r -d target.com -b -w /usr/share/seclists/Discovery/DNS/subdomains-top1million-5000.txt -o all_subs.txt
Pipe to resolver:
sublist3r -d target.com -o subs.txt
cat subs.txt | dnsx -silent -a -resp > live.txt
| File | When to load |
|------|--------------|
| references/ | Engine API keys and wordlist sources |
development
Auth/lab ref: Unicorn Engine CPU-only emulation for shellcode, decryptors, custom VM handlers, instruction tracing, memory hooks, and register-level experiments.
development
Auth/lab ref: Renode board and SoC simulation for MCU/RTOS firmware, UART/GPIO/peripheral modeling, GDB remote debugging, REPL platforms, and RESC scripts.
development
Auth/lab ref: Qiling OS-layer binary emulation for PE/ELF/Mach-O/UEFI/shellcode with rootfs, syscall/API hooks, filesystem mapping, and runtime patching.
databases
Auth/lab ref: QEMU user-mode and full-system emulation for cross-arch binaries, firmware, kernels, disks, serial consoles, networking, and GDB stubs.