projectdiscovery/subfinder
Fast passive subdomain enumeration tool. observed · 2026-08-28
Health v2 · maintenance only
95/100
- Activity 99
- Release rhythm 87
- Longevity 100
How is this computed?
round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-03. Adoption (stars, forks) is never an input.
- gap_med: 53
- age_days: 3077
- days_rel: 11
- days_push: 7
- n_releases_24m: 14
Adoption not part of the score
14315 stars · 1611 forks observed · 2026-08-28
What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-29, confidence not recorded
Subfinder is a fast, passive subdomain discovery tool written in Go that enumerates valid subdomains for target domains using online passive sources. It is designed for penetration testers and bug bounty hunters, with a modular architecture, STDIN/STDOUT support, and multiple output formats for easy pipeline integration.
Use cases
- enumerate subdomains of a domain for reconnaissance
- find subdomains for bug bounty targets
- passive OSINT subdomain discovery without touching the target
- build automated recon pipelines with stdin/stdout
- monitor an organization's external attack surface for new subdomains
- feed discovered subdomains into vulnerability scanners like httpx or nuclei
When to choose
- you need fast, stealthy passive subdomain enumeration without sending traffic to the target
- you want a lightweight CLI that integrates into shell pipelines and automation workflows
- you're a bug bounty hunter or pentester doing initial reconnaissance
- you need JSON or plain-text output for downstream tooling
When to avoid
- you need active subdomain brute-forcing or DNS resolution at scale - use tools like puredns or shuffledns instead
- you want a full attack surface management platform with continuous monitoring - consider ProjectDiscovery Neo or similar commercial offerings
- you need web application discovery and content crawling rather than just hostname enumeration
Facets
cli-tool · maturity active
osint security cli developer-tools security osint penetration-testing windows go cli cross-platform subdomain-enumeration reconnaissance bug-bounty passive-recon attack-surface command-line linux macos
5 sources
- readme: https://github.com/projectdiscovery/subfinder · fetched 2026-08-28 · 135370b18dde
- homepage: https://projectdiscovery.io · fetched 2026-08-29 · 4f86254fd766
- site_page: https://docs.neo.projectdiscovery.io/ · fetched 2026-08-29 · de87e1036abb
- site_page: https://docs.neo.projectdiscovery.io/use-cases/attack-surface-monitoring · fetched 2026-08-29 · e2b7027938c7
- site_page: https://projectdiscovery.io/pricing · fetched 2026-08-29 · 155f9d3a4107
Member repositories
| Repository | Role | Health v2 |
|---|---|---|
| projectdiscovery/subfinder | main | 95 |
For agents
markdown · JSON · MCP: product_card(name="projectdiscovery/subfinder")
Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem