Subdomain Enumeration with Subfinder, HTTPX & GPT-4-Mini for Security Reconnaissance
Generates a wordlist of 1,000–15,000 subdomains created by an AI agent by correlating detected technologies and recurring patterns. Objective Assist security researchers, bug bounty hunters, and web pentesters in the reconnaissance phase by incorporating an AI agent that generates additional potential subdomains. This enables discovery of assets outside the scope of traditional scans and expands the analyzable attack surface. How it works The user uploads a list of domains to scan (scope). The workflow performs a passive, comprehensive scan using four sources (subfinder, assetfinder, crt.sh, Wayback Machine). The scan results and detected technologies are passed to an AI agent. The agent runs in a loop up to 20 iterations, generating new subdomains each pass (average output depends on input and model). Generated subdomains are validated and deduplicated. Syntax is checked and availability is tested (host active / httpx). Requirements SSH access with a root user and the following tools:
Subfinder Assetfinder HTTPX
It is recommended to use a VPS with SSH because if the scope is very large the workflow will take a long time.
Related Templates
Use OpenRouter in n8n versions <1.78
What it is: In version 1.78, n8n introduced a dedicated node to use the OpenRouter service, which lets you to use a lot...
Task Deadline Reminders with Google Sheets, ChatGPT, and Gmail
Intro This template is for project managers, team leads, or anyone who wants to automatically remind teammates of tasks ...
🤖 Build Resilient AI Workflows with Automatic GPT and Gemini Failover Chain
This workflow contains community nodes that are only compatible with the self-hosted version of n8n. How it works This...
🔒 Please log in to import templates to n8n and favorite templates
Workflow Visualization
Loading...
Preparing workflow renderer
Comments (0)
Login to post comments