https://github.com/owasp-amass/amass
intel - collect further rootdomains associated with the organisation
enum - collect subdomains
Ask, Baidu, Bing, BuiltWith, DNSDumpster, DNSTable, HackerOne, RapidDNS, Riddler, SiteDossier, ViewDNS, Yahoo, Censys, CertSpotter, Crtsh, FacebookCT, GoogleCT, AlienVault, BinaryEdge, BufferOver, C99, CIRCL, CommonCrawl, DNSDB, GitHub, HackerTarget, IPToASN, Mnemonic, NetworksDB, PassiveTotal, Pastebin, RADb, Robtex, SecurityTrails, ShadowServer, Shodan, Spyse, Sublist3rAPI, TeamCymru, ThreatCrowd, ThreatMiner, Twitter, Umbrella, URLScan, VirusTotal, WhoisXML, ZETAlytics, ArchiveIt, LoCArchive, UKGovArchive, Wayback
# Path to config file and file example:
$HOME/.config/amass/config.yaml
# Insert:
options:
datasources: "<homeDir>/.config/amass/datasources.yaml"
# Example for datasources:
https://raw.githubusercontent.com/owasp-amass/amass/master/examples/datasources.yaml
# Execute
amass intel -d <domain> -whois --config <pathToConfigYaml>
amass intel -d <domain> -whois
amass intel -asn <asnNumber>
amass intel -ip -cidr <cidr>
amass intel -ip -addr <XXX.XXX.XXX.XXX-XXX>
Basic enumeration using different OSINT sources (passiv - no DNS resolution and validation, src show source)
amass enum -d <domain> -o <outputfile>