October 2, 2026
Subdomain Enumeration in Bug Bounty
In this article, I will be showing my methodology for subdomain enumeration and explaining why it is an important part of the bug bounty…

By Molapo Manuel
4 min read
In this article, I will be showing my methodology for subdomain enumeration and explaining why it is an important part of the bug bounty reconnaissance process. I will also discuss techniques commonly used by security researchers and demonstrate how I apply them in my own reconnaissance workflow. This includes both passive and active enumeration, web crawling, virtual host discovery, and HTTP probing to build a broader picture of a target's attack surface.
What Is Subdomain Enumeration?
Subdomain enumeration is the process of identifying subdomains that are connected to a specific domain.
For example, if we have the domain:
example.comexample.comA subdomain could be:
www.example.comwww.example.comIn this case, www is the subdomain.
Subdomain enumeration can lead to the discovery of exposed services, administrative panels, development environments, staging environments, and potentially vulnerable third-party applications.
Why Is Subdomain Enumeration Important?
Subdomain enumeration expands the attack surface of a target. Instead of focusing only on the main website, researchers can identify additional applications, services, APIs, and environments that may have different security configurations.
1. It Allows for More Attack Opportunities
Subdomain enumeration can discover hidden subdomains that contain their own services and configurations.
These discoveries can expose additional endpoints that may be affected by vulnerabilities such as:
- Broken Access Control
- IDOR (Insecure Direct Object Reference)
- Authentication weaknesses
- Privilege escalation
- Account takeover vulnerabilities
For example, an exposed endpoint with broken access controls could potentially allow unauthorized access to user information, administrative functionality, or other sensitive resources.
2. Exposure of Third-Party Services and Integrations
Subdomains can reveal third-party services and integrations that are part of an organization's infrastructure.
This can create additional attack opportunities, such as:
- Insecure APIs that expose sensitive data or functionality
- Unpatched third-party services vulnerable to known CVEs
- Misconfigured CORS policies that allow unauthorized cross-origin requests to sensitive endpoints
3. Forgotten or Outdated Applications
Organizations frequently remove servers, replace applications, or update their infrastructure. However, old subdomains can sometimes remain active and forgotten.
These forgotten applications can potentially contain:
- Outdated software with known CVEs
- Hardcoded credentials
- Test data
- Weak authentication mechanisms
- Poorly maintained applications
Because these systems may receive less attention and monitoring, they can become attractive targets for attackers.
Types of Subdomain Enumeration
There are two main approaches to subdomain enumeration:
- Passive Enumeration
- Active Enumeration
Passive Enumeration
Passive enumeration gathers information about subdomains without directly interacting with the target's infrastructure.
Researchers query third-party sources such as:
- Certificate Transparency logs
- Search engines
- WHOIS databases
- Web archives
- Public datasets
- Other external reconnaissance sources
The goal is to collect information without directly sending reconnaissance traffic to the target infrastructure.
This can reduce the likelihood of generating logs, alerts, or WAF events on the target.
Active Enumeration
Active enumeration directly interacts with the target infrastructure.
This can include:
- Sending DNS queries
- Brute-forcing subdomains using wordlists
- Crawling web applications
- Performing virtual host fuzzing
- Probing discovered hosts
Active enumeration can discover subdomains that have not been publicly indexed or identified through passive sources.
This can be particularly useful for discovering deeper or forgotten infrastructure.
Example Methodology
Now let's look at an example reconnaissance workflow.
The Passive Reconnaissance Phase
Researchers started with passive enumeration by using tools and public sources that collect subdomain information without directly interacting with ATG's infrastructure.
Step 1: Subfinder
Subfinder can query multiple passive sources to discover subdomains associated with a target.
subfinder -d atg.se -all -o subfinder_atg.txtsubfinder -d atg.se -all -o subfinder_atg.txtStep 2: crt.sh
Certificate Transparency logs can reveal subdomains that have appeared in SSL/TLS certificates.
curl -s "https://crt.sh/?q=%25.atg.se&output=json" | \
jq -r '.[].name_value' | sed 's/\*\.//g' | sort -u > crtsh_atg.txtcurl -s "https://crt.sh/?q=%25.atg.se&output=json" | \
jq -r '.[].name_value' | sed 's/\*\.//g' | sort -u > crtsh_atg.txtStep 3: Wayback Machine
Historical web archives can reveal subdomains and URLs that may no longer be linked from the current website.
curl -s "http://web.archive.org/cdx/search/cdx?url=*.atg.se/*&output=text&fl=original&collapse=urlkey" | \
sed 's|https\?://\([^/]*\).*|\1|' | sort -u > wayback_atg.txtcurl -s "http://web.archive.org/cdx/search/cdx?url=*.atg.se/*&output=text&fl=original&collapse=urlkey" | \
sed 's|https\?://\([^/]*\).*|\1|' | sort -u > wayback_atg.txtWhat they Found
The researchers discovered multiple subdomains that were not linked from any publicly visible page.
These included:
- Internal API endpoints
- Staging environments
- Regional variants of the main betting platform
This demonstrates why relying only on the main website can leave a large portion of an organization's attack surface undiscovered.
The Active Reconnaissance Phase
After collecting subdomains through passive enumeration, the researchers moved to active reconnaissance and brute-forcing.
Step 4: Gobuster DNS Brute-Force
Gobuster can be used to brute-force DNS subdomains using a wordlist.
gobuster dns -d atg.se -w ~/wordlists/subdomains-top1million-5000.txt -o gobuster_atg.txtgobuster dns -d atg.se -w ~/wordlists/subdomains-top1million-5000.txt -o gobuster_atg.txtThis approach attempts to discover additional subdomains that were not identified during the passive reconnaissance phase.
Step 5: Virtual Host Fuzzing With ffuf
Virtual host fuzzing can be used to test whether different hostnames are configured on the same web server.
ffuf -c -r -u 'https://www.atg.se/' -H 'Host: FUZZ.atg.se' -w ~/wordlists/dns-wordlist.txtffuf -c -r -u 'https://www.atg.se/' -H 'Host: FUZZ.atg.se' -w ~/wordlists/dns-wordlist.txtThe VHost Fuzzing Result
The ffuf results returned unusual HTTP responses for several subdomain names that did not have publicly resolvable DNS records.
This suggested that some of these names existed as virtual hosts on the same web server even though they were not publicly resolvable through DNS.
These could represent hidden applications sharing the same infrastructure.
The Web Crawling Phase
Researchers then used Burp Suite's embedded browser to navigate through:
www.atg.sewww.atg.seDuring this process, they passively collected subdomains and endpoints exposed through:
- The page's DOM
- API calls
- JavaScript bundles
- Other resources loaded by the application
"We collected a bunch of subdomains from a single domain visit. It's typical to get such a positive result, because modern websites tend to use multiple API endpoints and microservices, each with their own dedicated subdomain."
This demonstrates how a single web application can reveal additional parts of an organization's infrastructure during normal browsing.
The HTTP Probing Phase
After collecting subdomains from the different reconnaissance techniques, the results were merged and deduplicated.
cat subfinder_atg.txt crtsh_atg.txt wayback_atg.txt gobuster_atg.txt | sort -u > all_atg_subs.txtcat subfinder_atg.txt crtsh_atg.txt wayback_atg.txt gobuster_atg.txt | sort -u > all_atg_subs.txtThe resulting list could then be passed to httpx to identify which discovered hosts were actually serving HTTP or HTTPS services.
cat all_atg_subs.txt | httpx -silent -title -status-code -tech-detect -o live_cat all_atg_subs.txt | httpx -silent -title -status-code -tech-detect -o live_This allows researchers to identify live hosts and collect useful information such as:
- HTTP status codes
- Page titles
- Technologies being used
- Accessible web services
At this point, the reconnaissance process has transformed a collection of discovered subdomains into a more focused list of live targets that can be investigated further.
Conclusion
Subdomain enumeration is an important part of bug bounty reconnaissance because it helps researchers understand the target's external attack surface.
A good methodology should not rely on a single tool or source. Combining passive sources such as Subfinder, Certificate Transparency logs, and the Wayback Machine with active techniques such as DNS brute-forcing and virtual host fuzzing can provide a much broader view of the target's infrastructure.
Once the discovered subdomains have been collected, deduplicated, and probed for live services, researchers can move on to deeper testing of the applications and technologies exposed on those hosts.
The key idea is simple:
The main domain is only one part of the attack surface.