dnsreaper
subdomain takeover tool for attackers, bug bounty hunters and the blue team!
Name:dnsreaper
Category:Vulnerabilities
Publisher:trickest-mhmdiaa
Created:9/7/2022
Container:
quay.io/trickest/dnsreaper:dd7fa2a-patch-2
Output Type:
License:Unknown
Source:View Source
Parameters
aws
Scan multiple domains by fetching them from AWS Route53bind
Read domains from a dns BIND zone file, or path to multiplefile
Read domains from a file (or folder of files), one per lineazure
Scan multiple domains by fetching them from Azure DNS servicessingle
Scan a single domain by providing a domain on the commandline-v
Verbose output--nocolour
Turns off coloured text--pipeline
Exit Non-Zero on detection (used to fail a pipeline)--resolver
Provide a custom DNS resolver (or multiple seperated by commas)--signature
Only scan with this signaturecloudflare
Scan multiple domains by fetching them from Cloudflare--do-api-key
DigitalOcean API key (the `digitalocean` input must be set to true)--do-domains
Limit the scan to these domains (comma-separated)--filename
List of domains to scan (the `file` input must be set to true)--out-format
Output format (csv/json)--parallelism
Number of domains to test in parallel - too high and you may see odd DNS results (default: 30)--az-client-id
Azure client ID (the `azure` input must be set to true)--az-tenant-id
Azure tenant ID (the `azure` input must be set to true)digitalocean
Scan multiple domains by fetching them from Digital Oceanzonetransfer
Scan multiple domains by fetching records via DNS zone transfer-vv
Extra verbose output--domain
Scan this one domain (the `single` input must be set to true)--bind-zone-file
Bind zone file (the `bind` input must be set to true)--enable-unlikely
Check for more conditions, but with a high false positive rate--az-client-secret
Azure client secret (the `azure` input must be set to true)--cloudflare-token
Cloudflare token (the `cloudflare` input must be set to true)--disable-probable
Do not check for probable conditions--aws-access-key-id
AWS access key ID (the `aws` input must be set to true)--exclude-signature
Do not scan with this signature--az-subscription-id
Azure subscription ID (the `azure` input must be set to true)--zonetransfer-domain
Root domain to scan for (the `zonetransfer` input must be set to true)--aws-access-key-secret
AWS access key secret (the `aws` input must be set to true)--zonetransfer-nameserver
DNS server fqdn (such as ns1.domain.com) or IP address (the `zonetransfer` input must be set to true)