Skip to content

Assetfinder

Passive subdomain discovery tool that finds related domains and subdomains without directly touching the target.

Self-hostedNot yet verified
Report issue
MIT★ 3500Source project only — not browser-runnable

External Tool

This open-source tool is maintained externally. View the source on GitHub to learn more or run it yourself.

Browse security tools →

What's next with Assetfinder?

Choose how you want to get started.

Use it free

Open the official tool or demo — no account needed.

Free

Self-host it

Run the open-source version on your own infrastructure.

Open

What is Assetfinder?

Assetfinder is an open-source tool designed to identify domains and subdomains associated with a given domain. It serves as a reconnaissance tool for cybersecurity professionals, penetration testers, and researchers by aggregating data from multiple public sources to map an organization's digital footprint. The tool automates the process of discovering assets that may be overlooked during security assessments, helping users identify potential vulnerabilities or phishing targets. Its primary audience includes ethical hackers and security analysts who need to conduct network reconnaissance as part of penetration testing or threat intelligence gathering. By consolidating data from various APIs and databases, Assetfinder streamlines the discovery of hidden assets that could be exploited by malicious actors.

How it works

Assetfinder is a command-line utility that leverages public APIs and databases to uncover domains and subdomains linked to a target. It is part of the cybersecurity toolkit used for network mapping and reconnaissance. The tool's purpose is to simplify the process of gathering domain-related information, which is critical for identifying potential attack vectors or assessing an organization's online presence. Assetfinder integrates with sources like crt.sh, certspotter, and wayback machine to retrieve historical and current domain data. It also queries threatcrowd, virustotal, and hackertarget for known malicious or suspicious domains.

How to use it

  1. 1Install via Go with 'go get -u github.com/tomnomnom/assetfinder' or download a precompiled binary from the GitHub releases page. 2. Run the tool with 'assetfinder [target-domain]' to fetch domains. 3. Use '--subs-only' to focus solely on subdomains. 4. For Facebook integration, set environment variables for FB_APP_ID and FB_APP_SECRET before running. Practical tips: Combine results with tools like dnsenum or subfinder for deeper analysis. Monitor rate limits when using APIs like threatcrowd or Facebook.

What it can do

  • subdomain discovery

Use cases

Assumptions and limitations

Assumptions

  • source: https://github.com/tomnomnom/assetfinder
  • license: MIT — free to use
  • privacy: Self-hosted — you control your data

Limitations

  • Dual-use tool — use only with explicit authorization on systems you own or have permission to test.
  • Reliance on external APIs that may have rate limits or access restrictions
  • Inability to discover domains without public records or API access
  • Limited support for custom DNS enumeration beyond integrated sources
  • No real-time updates for domains or subdomains

Understanding the result

Passive subdomain discovery tool that finds related domains and subdomains without directly touching the target.

Tool details

  • Clearly flagged when a network request is needed.
  • No account, no sign-up, and no tracking of your content.
  • Powered by (MIT).
Built with
(tomnomnom/assetfinder)
License
MIT
Runs locally
No — requires a network request
Verification
Not yet verified
Input
Query
Output
Text
Open-source source & license

Built with tomnomnom/assetfinder. OpenToolVault provides the discovery and browser interface while crediting the original project maintainers.

Built with
License
MIT
View source on GitHub

Open-source project

OpenToolVault is an independent directory. We are not affiliated with or endorsed by this project.

References

Frequently asked

How do I install Assetfinder on a Linux system?

Install Go from the official website, then run 'go get -u github.com/tomnomnom/assetfinder' to fetch the tool. Alternatively, download a precompiled binary from the GitHub releases page and place it in your $PATH directory.

How does Assetfinder gather domain data?

The tool queries multiple public sources like crt.sh (for SSL certificates), wayback machine (for historical domains), and threatcrowd (for known malicious domains). It also leverages APIs from Facebook, Virustotal, and bufferover.run to aggregate data.

How do I use Facebook's API with Assetfinder?

Set the FB_APP_ID and FB_APP_SECRET environment variables with your Facebook app credentials. Ensure your app has access to the 'pages' permission. Run Assetfinder with the '--subs-only' flag to focus on subdomains linked to Facebook pages.

How does Assetfinder compare to tools like Sublist3r or Amass?

Assetfinder focuses on aggregating data from specific public sources, while Sublist3r and Amass use different methods like DNS brute-forcing or recursive subdomain discovery. Assetfinder excels at leveraging existing APIs, whereas Amass provides more granular DNS enumeration capabilities.

What should I do if Assetfinder returns an 'unrecognized flag' error?

Check the tool's documentation for valid flags. Common issues include typos in command-line arguments or using outdated versions. Update to the latest release via 'go get -u' or download a new binary from GitHub. Ensure your environment variables are correctly set for API integrations.

Spotted something wrong with Assetfinder, or want to maintain it? See how to help.