Subzy
Subdomain takeover vulnerability checker
Install / Use
/learn @PentestPad/SubzyREADME
Subzy
Subdomain takeover tool which works based on matching response fingerprints from can-i-take-over-xyz
<a href="https://twitter.com/intent/follow?screen_name=return_0x"> <img src="https://img.shields.io/twitter/follow/return_0x.svg?style=social&logo=twitter" alt="follow on Twitter"></a>
Installation
go install -v github.com/PentestPad/subzy@latest
If $GOBIN and $GOPATH are properly set, execute the program as:
$ subzy --help
Subdomain takeover tool
Usage:
subzy [command]
Available Commands:
help Help about any command
run Run subzy
version Print subzy version
Flags:
-h, --help help for subzy
Use "subzy [command] --help" for more information about a command.
If you get an error exec format error: ./subzy, you need to install Golang for your OS and compile the program by running go build -o subzy main.go which will generate new subzy binary file
Options
Only required flag for run subcommand(r short version) is either --target or --targets
--target (string) - Set single or multiple (comma separated) target subdomain/s
--targets (string) - File name/path to list of subdomains
--concurrency (integer) - Number of concurrent checks (default 10)
--hide_fails (boolean) - Hide failed checks and invulnerable subdomains (default false)
--https (boolean) - Use HTTPS by default if protocol not defined on targeted subdomain (default false)
--timeout (integer) - HTTP request timeout in seconds (default 10)
--verify_ssl (boolean) - If set to true, it won't check site with invalid SSL
Usage
Target subdomain can have protocol defined, if not http:// will be used by default if --https not specifically set to true.
-
List of subdomains
./subzy run --targets list.txt
-
Single or multiple targets
./subzy run --target test.google.com./subzy run --target test.google.com,https://test.yahoo.com
Command aliases
Each subzy subcommand has its own short version. Running subzy version or subzy v is the same.
- run - r
- update - u
- version - v
Related Skills
YC-Killer
2.7kA library of enterprise-grade AI agents designed to democratize artificial intelligence and provide free, open-source alternatives to overvalued Y Combinator startups. If you are excited about democratizing AI access & AI agents, please star ⭐️ this repository and use the link in the readme to join our open source AI research team.
groundhog
399Groundhog's primary purpose is to teach people how Cursor and all these other coding agents work under the hood. If you understand how these coding assistants work from first principles, then you can drive these tools harder (or perhaps make your own!).
sec-edgar-agentkit
10AI agent toolkit for accessing and analyzing SEC EDGAR filing data. Build intelligent agents with LangChain, MCP-use, Gradio, Dify, and smolagents to analyze financial statements, insider trading, and company filings.
last30days-skill
5.9kAI agent skill that researches any topic across Reddit, X, YouTube, HN, Polymarket, and the web - then synthesizes a grounded summary
