Subdomain Takeover Assistant

🏴‍☠️ Subdomain Takeover Assistant

Analyzes a list of subdomains to extract their CNAME records and cross-references the data with Cloud provider signatures (AWS, Azure, GitHub Pages) looking for potential infrastructure hijacks.

Frequently asked questions

What does it detect?
Subdomains pointing (CNAME) to abandoned services that could be claimed by an attacker (takeover).
Is it legal?
Checking your own subdomains is fine; claiming third-party ones is not.
Is it useful for bug bounty?
Yes, it is a common check.