Sitelet https://github.com/sbilly/awesome-security/pull/756
Skip to content

Add SubSniper — zero-dependency subdomain takeover scanner - #756

Open
AmirDiaz wants to merge 1 commit into
sbilly:masterfrom
AmirDiaz:add-subsniper
Open

AmirDiaz wants to merge 1 commit into
sbilly:masterfrom
AmirDiaz:add-subsniper

Conversation

@AmirDiaz

@AmirDiaz AmirDiaz commented Oct 3, 2026

Copy link
Copy Markdown

What is SubSniper?

SubSniper is a subdomain takeover scanner built as a single-file, zero-dependency Python tool (pure stdlib — no pip installs).

Pipeline: passive enumeration (crt.sh, OTX, urlscan, RapidDNS) → DNS triage (live/dangling classification) → raw-UDP CNAME extraction (no dnspython needed) → HTTP fingerprinting against 40+ takeover signatures (AWS S3, Heroku, Vercel, GitHub Pages, Azure Cloud, Pantheon, Shopify, Zendesk, Fastly, Surge.sh, …) → markdown + JSON reports.

It also flags live hosts whose CNAMEs point at claimable services (wildcard cases).

git clone https://github.com/AmirDiaz/subsniper.git
python3 subsniper.py example.com

MIT licensed. Fits the list's format — one line, same style as the other entries. Happy to adjust the description if needed.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant