XowiaScan
← All tools

Subdomain Discovery

Recon & Discovery

Aggregate a domain’s subdomains from multiple passive sources into one de-duplicated, exportable list.

What is Subdomain Discovery?

Subdomain Discovery widens your attack surface without touching the target. It queries several public intelligence sources in parallel — Certificate Transparency logs, threat-intel feeds and certificate databases — and merges the results into a single clean list of hostnames tied to the domain.

Because it relies on passive data sources rather than brute force, it is quiet, fast and ideal for the earliest phase of recon when you are mapping everything an organization exposes.

What it does

  • Certificate Transparency (crt.sh) — pulls every hostname ever issued a TLS certificate under the domain.
  • Threat-intel feeds (AlienVault OTX) — adds hosts seen in passive DNS and indicators.
  • Certificate databases (CertSpotter) — catches recently issued certs CT may have missed.
  • Shodan — surfaces hosts indexed by internet-wide scanning.
  • De-duplication & normalization — collapses wildcards and duplicates into a clean, sorted set.
  • Export — copy or download the full list as text/CSV for piping into your next tool.

Where it fits in your workflow

  • Map an organization’s footprint before choosing where to dig deeper.
  • Feed the results into HTTP ProbeMaster to find which hosts are live.
  • Cross-check against the Subdomain Takeover Scanner for dangling CNAMEs.
Use Subdomain Discovery

Run it from your dashboard.

Create free account Sign in Use via API

At a glance

CategoryRecon & Discovery
RunsServer-side
Token cost 5 / run (free tier)
AccessPro
Status● Live

Frequently asked questions

Does this brute-force subdomains?

No — it is fully passive. It reads from public certificate logs and intelligence feeds, so the target never receives traffic from your enumeration.

Why do some subdomains no longer resolve?

Passive sources include historical records. Run the live hosts through HTTP ProbeMaster or the DNS checker to confirm which are still active.

Explore more tools →