Subdomain enumeration
TL;DR
Organisations have far more exposed than their main website — dev sites, old apps, admin panels, forgotten services, all living on subdomains. Enumerating them expands your attack surface, and the forgotten ones are often the way in.
What it is
Finding the hostnames that belong to a target: app.example.com, dev.example.com, vpn.example.com and so on. The main site is usually well looked after; the extras often aren’t.
How it works
- Passive: pull names from certificate transparency logs, DNS datasets and search engines — no traffic to the target.
- Active: resolve a wordlist of likely names against the target’s DNS to find ones that aren’t published anywhere.
- Then check which are actually alive and what’s running on them.
Why it matters
The interesting findings are rarely on the polished front door. A staging site with debug on, an old app that never got patched, a login panel nobody remembers — that’s what enumeration surfaces, and it’s often where a test really starts.