Lightning-fast subdomain enumeration with optimized algorithms
Secure data handling and encrypted result storage
Multi-threaded operations for maximum efficiency
Automated sorting and categorization of results
Combination of DNS brute-forcing and OSINT methods
Professional reconnaissance with VirusTotal and DNSDumpster APIs
Leverage VirusTotal's massive threat intelligence database to discover subdomains from historical scans and passive DNS records.
Comprehensive DNS mapping including historical records, MX configurations, and network infrastructure discovery.
Leverage GitHub's code search API to find subdomains exposed in public repositories, commit histories, and gists.
$ subfors -d example.com
$ subfors -d example.com -oJ op.json -oX op.xml -o op.txt
$ subfors -d example.com -vt abc123def456ijweioqu121o2
$ subfors -d example.com -dn xyz789uvw01229jvweiji223incq
$ subfors -d example.com -gt ghp_abcd1234xyzjwejnkjnasnas
$ subfors -dL scop.txt -t 60 -timeout 20