BigHugger
sk Skill · UseOSINT

find-hidden-subdomains

Enumerate an organisation's subdomains and sibling domains from Certificate Transparency logs and passive DNS, without sending traffic to the target. Covers crt.sh and CT log queries, certificate SAN fields, subfinder and amass, and newly issued TLS certificates. Use when looking for staging, dev, admin or VPN hosts, mapping the full hostname footprint of a domain, or spotting infrastructure a company forgot it had.…

installs 8w
1,636
30-day movement
starts with the next reading
Related entries
1
Connections
0
bashShell

An agent skill that teaches enumerating an organisation's subdomains and sibling domains from Certificate Transparency logs and passive DNS, without sending traffic to the target. It covers crt.sh queries, SAN fields, subfinder and amass, confidence grading, and how to interpret name patterns like dev, staging, vpn and admin.

It gives you a structured, passive-only method for mapping a domain's full hostname footprint before any active scanning.

Use it to

  • Map the full hostname footprint of a target domain
  • Find forgotten staging, dev, admin or VPN hosts
  • Review vendor or supply-chain attack surface
  • Discover brand-infringement lookalike domains
  • Support M&A technical diligence on a company's infrastructure

For Security researchers and OSINT practitioners doing passive reconnaissance

Host repository
UseOSINT/Skills
Installs, lifetime
1,600
Installs, 8 weeks
1,636
Host stars
37
Host language
Shell
topicsosintsubdomain-enumerationcertificate-transparencypassive-dnsattack-surfacereconnaissance