21/02/2026
🚀 Advanced Subdomain Hunter – Automated Recon Framework
I built a Bash automation tool for passive subdomain enumeration to reconnaissance during pe*******on testing and bug bounty program.
🔎 Overview
This tool automates multiple industry-standard OSINT enumeration utilities and consolidates their output into a single, clean, deduplicated result set.
attached tools:
👉🏻 Subfinder
👉🏻 OWASP Amass
👉🏻 Sublist3r
✅ Passive Enumeration
Each tool runs in passive mode to avoid active probing:
Subfinder → Collects subdomains from multiple OSINT sources
Amass (Passive) → Gathers data from public intelligence datasets
Sublist3r → Extracts subdomains via search engine enumeration
This ensures safe reconnaissance aligned with responsible disclosure practices.
✅ Reporting
The script automatically:
Counts total unique subdomains
Displays a clean summary
Provides the final output path
🎯 Key Features
✔ Multi-tool automation
✔ Passive reconnaissance only
✔ Regex-based validation
✔ Duplicate removal
✔ Structured output management
✔ Timestamp-based versioning