• Tutorials
  • Courses
  • Tracks

Which technique is least likely to find hidden subdomains?

Last Updated :
Discuss
Comments

Which technique is least likely to find hidden subdomains?

Brute-force a wordlist of probable subdomains (e.g., www, dev, api)

Query Certificate Transparency logs for issued certificates

Query historical DNS/archived DNS datasets (passive DNS)

Scanning only for open TCP port 22 on random IP addresses without referencing DNS records

Share your thoughts in the comments