Aggregate a domain’s subdomains from multiple passive sources into one de-duplicated, exportable list.
Subdomain Discovery widens your attack surface without touching the target. It queries several public intelligence sources in parallel — Certificate Transparency logs, threat-intel feeds and certificate databases — and merges the results into a single clean list of hostnames tied to the domain.
Because it relies on passive data sources rather than brute force, it is quiet, fast and ideal for the earliest phase of recon when you are mapping everything an organization exposes.
No — it is fully passive. It reads from public certificate logs and intelligence feeds, so the target never receives traffic from your enumeration.
Passive sources include historical records. Run the live hosts through HTTP ProbeMaster or the DNS checker to confirm which are still active.