finds.dev← search

// the find

tomnomnom/assetfinder

★ 3,682 · Go · MIT · updated Jun 2024

Find domains and subdomains related to a given domain

A single-purpose Go CLI that pulls subdomains for a domain from a handful of passive sources like crt.sh, the Wayback Machine, and a few API-gated services. Built for pentesters and bug bounty hunters doing recon, meant to be piped into other tools rather than used standalone.

Does one thing and stays out of the way — no config file, just a binary and a domain argument, which is why it ended up in half of every recon one-liner on Twitter. Concurrent source queries keep it fast even though it's hitting several external APIs sequentially per-source. Small, readable codebase (one file per source) that's trivial to fork and add a source to.

Last pushed mid-2024 and several of its sources are already dead weight: threatcrowd shut down years ago, spyse got acquired and the API/key scheme in the README no longer applies, so a chunk of 'Implemented' sources silently return nothing. The TODOs (flag to select sources, stdin input) have been sitting unaddressed for years, so you can't disable a broken source without editing source. No tests in the repo, and no rate-limit backoff visible beyond a single ratelimit.go — easy to get IP-banned from crt.sh on larger domains.

View on GitHub →

// want more like this?

We dig through GitHub every week and send a few repos picked for what you actually care about — each with an honest take like this one.

Get finds in your inbox → Search again →