# screetsec/Sudomy

Sudomy is a subdomain enumeration tool to collect subdomains and analyzing domains performing automated reconnaissance (recon) for bug hunting / pentesting

Repository: https://github.com/screetsec/Sudomy
Canonical: https://ross.abutalabs.com/products/sudomy
Homepage: https://github.com/Screetsec/
Language: Shell
License: MIT
License Family: permissive
Topics: bugbounty, subdomain-enumeration, scanner, enumeration, reconnaissance, pentesting, hackerone, bugcrowd, kali, kali-linux, bash, httprobe, sublist3r, subfinder, collected-subdomains, subdomain-scanner, subdomain-finder, recon-subdomain, framework
Last push: 2024-06-27T10:07:42+00:00

## Health v2 (maintenance only)
Score: 23/100 (v2, computed 2026-09-02T17:46:02.011165+00:00)
- activity 0, release rhythm 8, longevity 100
- inputs: {"age_days": 2595, "days_push": 797, "days_rel": null, "gap_med": null, "n_releases_24m": 0}
- flags: none
- formula: round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)

## Adoption (not part of the score)
Stars 2432, forks 416 (observed 2026-08-28T04:06:51.156250+00:00)

## What it is
Sudomy is a Bash-based subdomain enumeration and reconnaissance framework that collects subdomains via active brute-forcing and passive third-party data sources, then analyzes them for live hosts. It is aimed at bug bounty hunters and penetration testers performing automated domain recon.

## Use cases
- enumerate subdomains of a target domain for a bug bounty program
- passively collect subdomains from OSINT sources like crt.sh and VirusTotal
- brute-force DNS subdomains with a large wordlist
- probe discovered subdomains for live HTTP/HTTPS servers
- automate reconnaissance workflow before a pentest engagement

## When to choose
- you need a fast, scriptable recon tool that runs on plain Linux or WSL without heavy dependencies
- you want to combine passive OSINT collection with active DNS brute-forcing in one tool
- you are doing bug bounty or pentest reconnaissance on a domain

## When to avoid
- you need a maintained, actively developed tool with recent community support
- you want a GUI or Windows-native experience
- you need continuous asset monitoring rather than point-in-time enumeration

## Facets
- artifact type: cli-tool
- maturity: maintenance
- function: security, osint, web-scraping, cli, developer-tools
- domain: security, penetration-testing, osint, developer-tools
- platform: cli, windows
- tags: subdomain-enumeration, reconnaissance, bug-bounty, pentesting, dns, bash, recon-framework, command-line, linux

## Member repositories
- screetsec/Sudomy (main) score 23

## Provenance
- Observed fields: from GitHub, fetched 2026-08-28T04:06:51.156250+00:00.
- Health v2: computed from the inputs above; adoption is never an input.
- Inferred fields (summary, facets, guidance): AI-extracted, prompt v1, taxonomy v1, on 2026-08-30T02:31:17.159456+00:00, confidence not recorded.
  - readme: https://github.com/screetsec/Sudomy (fetched 2026-08-28T04:06:51.156250+00:00, sha dd87638d813e)
  - homepage: https://github.com/Screetsec/ (fetched 2026-08-29T10:12:33.532579+00:00, sha e9791444fd1a)
- Data as of 2026-08-30T08:39:29.467469+00:00.
