A streamlined bash script designed to automate the initial reconnaissance and enumeration phases of a penetration test or bug bounty hunt. This script ties together popular command-line tools to discover subdomains, filter for active hosts, and perform basic port scanning.
- Automated Directory Structuring: Automatically creates organized folders for your target to keep scan results tidy.
- Subdomain Harvesting: Uses
assetfinderto quickly gather potential subdomains. - Alive Host Probing: Filters the gathered subdomains with
httprobeto identify which hosts are actively responding on HTTPS (port 443). - Port Scanning: Passes the live hosts to
nmapfor a rapid initial port scan. - (Optional/Commented): Built-in hooks for
amassif you want to expand subdomain discovery.
Ensure you have the following tools installed and accessible in your system's $PATH:
- assetfinder
- httprobe
- nmap
- (Optional) amass - Currently commented out in the script, but can be uncommented for deeper enumeration.
- Clone the repository:
git clone [https://github.com/SureshDeora/Web-Enumeration-Automation.git](https://github.com/SureshDeora/Web-Enumeration-Automation.git) Navigate to the directory:
Bash cd Web-Enumeration-Automation Make the script executable:
Bash chmod +x run.sh π» Usage Run the script by passing the target domain as an argument:
Bash ./run.sh example.com π Output Structure When you run the script against example.com, it generates the following directory structure in your current working directory:
Plaintext example.com/ βββ recon/ βββ final.txt # Final list of raw subdomains βββ httprobe/ β βββ alive.txt # List of active subdomains (HTTPS) βββ scans/ βββ scanned.txt.nmap # Nmap scan output files βββ scanned.txt.gnmap βββ scanned.txt.xml βοΈ How It Works (Under the Hood) Initialization: Checks if a directory for the target domain exists; if not, creates one along with a recon/ subdirectory.
Subdomain Enumeration: Runs assetfinder against the target and greps for the domain to filter out noise.
Probing: Pipes the sorted, unique subdomains into httprobe to check for active connections on port 443, stripping the protocol headers for clean IP/domain lists.
Scanning: Uses nmap -T4 against the active hosts to quickly identify open ports and outputs the results in all formats (-oA).