Censys Subdomain Finder – Perform Subdomain Enumeration Using The Certificate Transparency Logs From Censys

This is a tool to enumerate subdomains ^(http://www.kitploit.com/search/label/Subdomains) using the Certificate Transparency ^(http://www.kitploit.com/search/label/Transparency) logs stored by Censys ^(https://censys.io/). It should return any subdomain who has ever been issued a SSL certificate by a public CA.

https://censys.io/register ^(https://censys.io/register)

  • Browse to https://censys.io/account ^(https://censys.io/account), and set two environment variables with your API ID and API secret
  • $ export CENSYS_API_ID=...
    $ export CENSYS_API_SECRET=...
    1. Clone the repository
    $ git clone https://github.com/christophetd/censys-subdomain-finder.git
    1. Install the dependencies
    $ cd censys-subdomain-finder
    $ pip install -r requirements.txt
    1. Run the script on example.com to make sure everything works as expected.
    $ python censys_subdomain_finder.py example.com

    [*] Searching Censys for subdomains of example.com
    [*] Found 5 unique subdomains of example.com

    - products.example.com
    - www.example.com
    - dev.example.com
    - example.com
    - support.example.com

    Usage

    usage: censys_subdomain_finder.py [-h] [-o OUTPUT_FILE]
    [--censys-api-id CENSYS_API_ID]
    [--censys-api-secret CENSYS_API_SECRET]
    domain

    positional arguments:
    domain The domain to scan

    optional arguments:
    -h, --help show this help message and exit
    -o OUTPUT_FILE, --output OUTPUT_FILE
    A file to output the list of subdomains to (default:
    None)
    --censys-api-id CENSYS_API_ID
    Censys API ID. Can also be defined using the
    CENSYS_API_ID environment variable (default: None)
    --censys-api-secret CENSYS_API_SECRET
    Censys API secret. Can also be defined using the
    CENSYS_API_SECRET environment variable (default: None)

    Compatibility
    Should run on Python 2.7 and 3.5.

    Notes
    The Censys API has a limit rate of 120 queries per 5 minutes window. Each invocation of this tool makes exactly one API call to Censys.
    Feel free to open an issue ^(https://github.com/christophetd/censys-subdomain-finder/issues/new) or to tweet @christophetd for suggestions or remarks.

    Download Censys-Subdomain-Finder ^(https://github.com/christophetd/censys-subdomain-finder)

    Author: Marshmallow

    Marshmallow Android is BT Ireland’s Head of Sales for Republic of Ireland domestic multi-site companies, indigenous MNCs and public sector accounts. He is responsible for the direction and control of all sales activity in the region. He has over 10 years management experience from high growth start-ups to more established businesses. He’s led teams in Ireland, India and China across various industries (ICT, On-Line Recruitment, Corporate Training and International Education).