Skip to content
Go

SubX

SubX is an all-in-one subdomain recon tool written in Go. It discovers subdomains from 5+ sources (crt.sh, VirusTotal, SecurityTrails, AlienVault, Wayback), resolves DNS, detects Cloudflare, scans ports, retrieves SSL/WHOIS/ASN/BGP, and checks hashes against VirusTotal — with a real-time streaming web UI.

0

Stars

0

Forks

0

Watchers

0

Issues

6925

Size (KB)

master

Branch

Files

2 folders · 6 files

Click a file to open it on GitHub. Browse full tree →

<div align="center">
<h1>SubX</h1>
<p><strong>All-in-one subdomain enumeration & reconnaissance tool</strong></p>
<p>
<img src="https://img.shields.io/badge/Go-1.21%2B-00ADD8?logo=go" />
<img src="https://img.shields.io/badge/license-MIT-blue" />
</p>
<p>
Subdomain discovery · DNS resolution · Cloudflare detection · Port scanning ·<br>
SSL info · WHOIS/ASN/BGP · VirusTotal check · Real-time web UI
</p>
</div>

---

Overview

SubX is a comprehensive subdomain reconnaissance tool written in Go that combines 5 subdomain sources, DNS analysis, network scanning, and threat intelligence into one fast CLI + web tool. It features a real-time streaming web UI powered by Server-Sent Events (SSE) so you can watch scans unfold live in the browser.

Features

Subdomain Enumeration


  • crt.sh — Certificate Transparency log search (no API key needed)

  • VirusTotal — Subdomain lookup via VirusTotal API

  • SecurityTrails — DNS history and subdomain discovery

  • AlienVault OTX — Open Threat Exchange pulse indicators

  • Wayback Machine — CDX archive subdomain extraction

  • Brute Force — DNS brute force with custom wordlist (-w flag)


DNS & Network


  • A record resolution — resolves all discovered subdomains

  • NS / MX / TXT — nameserver, mail exchange, and text records

  • Reverse DNS (PTR) — IP to hostname lookup

  • Cloudflare detection — per-subdomain and network-level proxy detection via IP range matching

  • Wildcard filter — detects and removes wildcard DNS entries

  • SSL certificate info — issuer, subject, expiry date, days remaining

  • WHOIS / ASN — IP geolocation, ISP, AS number, AS name, organization

  • BGP prefix / CIDR — IP range and total IP count

  • Port scanning — 26 common ports with service and banner detection


VirusTotal Integration


  • Check file hashes (SHA-256, MD5)

  • Check IP addresses, URLs, and domains

  • Shows malicious / suspicious / harmless counts

  • Lists individual engine detection results

  • Direct permalink to VirusTotal analysis


Web UI


  • Real-time streaming logs (SSE) — watch every step as it happens

  • Domain scan tab with source selection and port scan toggle

  • VT check tab for hash / IP / URL / domain lookup

  • API key status badges

  • Results displayed with stats grid, network info table, open ports, and subdomains table with Cloudflare badges


Output Formats


  • CLI — formatted terminal output with color indicators

  • JSON — machine-readable output (-json flag)

  • File — save resolved subdomains to file (-o flag)


Installation

From Source

git clone https://github.com/TEGAR-SRC/SubX.git
cd SubX
go build -o subx.exe .\cmd\subfinder\ # Windows
go build -o subx ./cmd/subfinder/ # Linux / macOS

Pre-built Binaries

Download the latest release from the Releases page.

Quick Start

# Basic scan with VirusTotal + SecurityTrails
subx -d example.com -sources virustotal,securitytrails

Full scan with all sources + port scan


subx -d example.com -scan

Web UI (open http://localhost:8080)


subx -web 8080

VirusTotal hash check


subx -check d41d8cd98f00b204e9800998ecf8427e

Save results to file


subx -d example.com -o subs.txt

JSON output


subx -d example.com -json

Brute force with wordlist


subx -d example.com -w wordlist.txt

Custom thread count and timeout


subx -d example.com -t 20 -timeout 30

API Keys

Create a .env file in the same directory as SubX (auto-loaded):

VT_API_KEY=your_virustotal_api_key
ST_API_KEY=your_securitytrails_api_key
OTX_API_KEY=your_alienvault_otx_api_key

Or set them as environment variables:

# Windows
set VT_API_KEY=your_key

Linux / macOS


export VT_API_KEY=your_key

Where to get API keys

| Key | Source | Sign Up |
|-----|--------|---------|
| VT_API_KEY | VirusTotal | https://www.virustotal.com/gui/my-apikey |
| ST_API_KEY | SecurityTrails | https://securitytrails.com/app/signup |
| OTX_API_KEY | AlienVault OTX | https://otx.alienvault.com/settings |

Usage

CLI Reference

subx -d <domain> [-sources <list>] [-scan] [-w <file>] [-t <n>] [-timeout <s>] [-o <file>] [-json] [-no-wildcard] [-all]

subx -web <port>

subx -check <hash|ip|url|domain>

| Flag | Default | Description |
|------|---------|-------------|
| -d | — | Target domain |
| -sources | all | Comma-separated sources: crtsh,alienvault,wayback,virustotal,securitytrails |
| -scan | false | Enable port scanning (26 common ports) |
| -w | — | Wordlist file for DNS brute force |
| -t | 10 | Number of concurrent threads |
| -timeout | 15 | Request timeout in seconds |
| -o | — | Output file for resolved subdomains |
| -json | false | Output results in JSON format |
| -no-wildcard | true | Filter wildcard DNS entries |
| -all | false | Show unresolved subdomains |
| -web | — | Start web UI on specified port |
| -check | — | Check hash, IP, URL, or domain on VirusTotal |
| -show-sources | false | List available sources and exit |

Examples

# Scan with specific sources
subx -d example.com -sources crtsh,alienvault,wayback

Full recon with port scan


subx -d example.com -sources virustotal,securitytrails -scan -t 20

Brute force subdomains


subx -d example.com -w subdomains.txt -t 50

Export results as JSON


subx -d example.com -json -o results.json

VT check with custom timeout


subx -check 8.8.8.8 -timeout 10

Show all subdomains including unresolved


subx -d example.com -all

Web UI

Start the web dashboard:

subx -web 8080

Open http://localhost:8080.

The web UI features:

  • Domain Scan tab — enter a domain, select sources, toggle port scan and wildcard filter

  • VT Check tab — paste a hash, IP, URL, or domain for VirusTotal analysis

  • Real-time logs — watch each step of the scan as it happens (SSE streaming)

  • Results — stats grid, network info (IPs, NS, MX, ASN, CIDR, location, SSL), open ports table, and detailed subdomains table with Cloudflare proxy badges


Sources Detail

| Source | Auth | Description |
|--------|------|-------------|
| crtsh | None | Certificate Transparency log via crt.sh |
| alienvault | OTX_API_KEY | AlienVault Open Threat Exchange |
| wayback | None | Internet Archive Wayback Machine CDX |
| virustotal | VT_API_KEY | VirusTotal passive DNS |
| securitytrails | ST_API_KEY | SecurityTrails DNS history |

When -sources all is used, all sources with valid API keys are enabled.

Architecture

cmd/subfinder/main.go          — Entry point, CLI flag parsing, .env loader
internal/
├── dns/dns.go — DNS resolution, Cloudflare detection, wildcard filter, NS/MX/TXT/PTR
├── network/network.go — Port scanner, SSL, WHOIS, BGP prefix, service detection
├── runner/runner.go — Orchestrator, source collector, brute force, output, JSON
├── sources/
│ ├── crtsh.go — crt.sh API
│ ├── alienvault.go — AlienVault OTX API
│ ├── wayback.go — Wayback Machine CDX
│ ├── virustotal.go — VirusTotal API (subdomains + hash check)
│ └── securitytrails.go — SecurityTrails API
└── web/server.go — Web UI with SSE streaming

Building

# Build for current platform
go build -o subx .\cmd\subfinder\

Cross-compile


$env:GOOS="linux"; $env:GOARCH="amd64"; go build -o subx-linux .\cmd\subfinder\
$env:GOOS="darwin"; $env:GOARCH="amd64"; go build -o subx-macos .\cmd\subfinder\

License

MIT

Repository metadata

Owner
TEGAR-SRC
Primary language
Go
License
Not declared
Created
Jul 24, 2026
Last pushed
Jul 24, 2026
Last updated
Jul 24, 2026

Clone this repository

HTTPS

git clone https://github.com/TEGAR-SRC/SubX.git

SSH

git clone git@github.com:TEGAR-SRC/SubX.git

More Go repositories