Subdomain takeover scanner: detecting dangling CNAME records pointing to abandoned cloud services
A recon tool that resolves a subdomain list, fingerprints their CNAME targets against known "unclaimed service" signatures (GitHub Pages, S3, Heroku, etc.), and flags the ones ripe for takeover.
The full write-up is locked
Unlock the step-by-step write-up, screenshots and PoC file for free.
A recon tool that resolves a subdomain list, fingerprints their CNAME targets against known "unclaimed service" signatures (GitHub Pages, S3, Heroku, etc.), and...…
Browse the file tree freely — unlock to download.
-
subdomain_takeover_scanner.py 1.7 KB
Offensive tooling labs
View all labsNo related labs for this topic yet.
Reviews & Questions
Sign in to ask a question or leave a review.
No reviews or questions yet — be the first.
Listing Details
- Author
- hex_weaver
- Published
- 2026-09-13
- Target / OS
- An organization's subdomain inventory (external recon phase)
- Category
- Scripts & Tools
- Payout Method
- No preference
Price
FREE
No payment required
Live Chat
Ask the seller or other buyers a question — mention someone with @handle
No messages yet — start the conversation.
Sign in to join the conversation.