Skip to content
Another Subdomain ENumeration Tool
Python
Branch: master
Clone or download

Latest commit

Fetching latest commit…
Cannot retrieve the latest commit at this time.

Files

Permalink
Type Name Latest commit message Commit time
Failed to load latest commit information.
as3nt
screenshots
.gitignore
CHANGELOG.md
LICENSE init commit Feb 21, 2020
README.md updated readme Feb 26, 2020
requirements.txt
setup.py

README.md

Version 1.0.1 Python 3.8 GPL License

As3nt

Another Subdomain ENumeration Tool - written in python to enumerate and enrich subdomains using passive OSINT.

As3nt can target TLDs or subdomains. The enumeration uses; VirusTotal, HackerTarget, ThreatCrowd, ThreatMiner, BufferOver, urlscan.io and crt.sh. Each subdomain IP is resolved using public DNS servers and the data is enriched using ipwhois and Shodan. As3nt currently outputs to terminal or csv.

Along with using the tags from Shodan, this tool also adds it's own tags. Currently there are tags added based on certain HTML content found by Shodan like tomcat, fortinet, netscaler and pulse vpn. Also if any CVEs are found for an IP/Subdomain with a CVSS score >= 7.8, these assets are tagged to highlight a possible exploit.

Screenshots

As3nt_1
As3nt_2

Installation

  1. Install:
  • with pip: pip install as3nt
  • from git (source):
    • git clone https://github.com/cinerieus/as3nt.git && cd as3nt/
    • pip install -r requirements.txt
    • python ./as3nt/core.py
  • from git (releases):
    • wget https://github.com/cinerieus/as3nt/archive/v1.0.1.tar.gz
    • pip install v1.0.1.tar.gz
  1. Remember to check PATH if you installed in ~/.local/bin/
  2. Profit!

*For Shodan functionality set the environment variable 'SHODANKEY' with your API key.

Dependencies

See requirements.txt

Changelog

See CHANGELOG.md

Usage

usage
*If selected Shodan is rate-limited to 1 IP per second.

Examples:

  • Run all modules against 'example.com' and save results to csv:
    as3nt -t example.com -11 -o results.csv
  • Run against a subdomain:
    as3nt -s -t subdomain.example.com -11 -o results.csv

Thanks

You can’t perform that action at this time.