Hacker News new | ask | show | jobs
by bashwizard 468 days ago
Like people have said already; Certificate Transparency logs.

There are countless of tools to use for subdomain enumeration. I personally use subfinder or amass when doing recon on bug bounty targets.