Skip to main content

Subdomain Discovery

If you've got an attack surface that can't be mapped, this is the feature for you.

Written by Naomi Purvis

🎫 Plan availability: Subdomain discovery is available on Enterprise and Vanguard plans.

What can it do?

Discover subdomains of existing apex domains that have been added to the portal. ie., if you have added example.com, we might return portal.example.com or api.example.com.

How does it work?

For our Enterprise and Vanguard clients, we run an automatic daily scan on all your targets to check for any subdomains that have not yet been added to the tool. For our Cloud and Pro plan customers, the scans run weekly.

Intruder’s detection mechanisms use various methods, including DNS reconnaissance and passive DNS sources. This dual approach enhances the accuracy of the scans.

Should we find any, we'll send you an email:

We'll also list them on your Subdomain detection page. If unexpected subdomains are detected, investigate whether they stem from deliberate creation, wildcard DNS, or passive DNS behavior. You can exclude unintended subdomains via the interface to only include relevant scanning targets.

How can I manage them?

Excluding apex domains permanently

Some apex domains identified during discovery may not be relevant to your organization, or you may not want to track them. In these cases, you can now permanently exclude an apex domain.

When you permanently exclude an apex domain:

  • All of its currently discovered subdomains are excluded immediately.

  • Future discovery scans will no longer return that apex domain or any associated subdomains.

  • Any subdomains you have already added as targets remain in your Targets list. Only future discovery of new subdomains beneath that apex domain stops; nothing previously added as a target will be removed.

To permanently exclude an apex domain, expand the domain group in the Subdomain Detection view and select Exclude:

When the following modal appears, review the information presented and click Exclude:

Excluding individual subdomains

If you want to keep the apex domain active but remove only certain discovered subdomains, you can use the bulk‑select checkboxes and the Exclude action. This removes only the selected subdomains. Future discoveries beneath that apex domain will continue to appear.

Managing discovered subdomains

On the Subdomain detection page, you can sort by Most subdomains, Least subdomains, Newest subdomains, and Oldest subdomains:

Clicking on them will open the list of associated subdomains:

The Discovered tab shows subdomains that have not been added as targets:

The Added tab shows subdomains that have been added as targets, which means they are now included in the target list and will be subject to scanning (pending license availability):

The Excluded tab shows excluded subdomains:

  • To exclude a discovered subdomain, open the Discovered tab, check the box to the left of the subdomain, and click Exclude:

  • To restore an excluded subdomain, open the Excluded tab and click Restore:

If we have detected targets that appear to be hosted on a cloud provider such as Google Cloud, AWS, or Azure, we'll also flag this on the Discovery page to allow you to integrate with the cloud platform by clicking the 'Add Integration' button, if you'd like:

If you believe a subdomain is missing from the list, let us know. Click '•••' > Missing subdomains:

Add the name of the missing subdomain and some details in the box (the more details, the better, as this will help our team improve the results over time) > hit Submit or Submit and add target:

If you hit Submit and add target, your comment will be submitted, and you have the option to add the missing subdomain from this modal:

Where do I manage the emails?

You can manage them from Settings > Notifications:


FAQs

Can it find 'associated' domains?

No, unfortunately, the subdomain discovery feature itself doesn't.

However, we do have a Related Domain Discovery feature, which will enable you to find domains related to existing apex domains that have been added to the portal. ie. If you have added exampletest.com, we might return exampletester.com or exampletest.co.uk.

Are the discovered subdomains automatically added to the portal?

No, we don't automatically add them – we leave that up to you, the user.

Do we show existing targets on the Subdomain detection page?

Yes, if a target has already been added, it will be visible in the Added section:

Did this answer your question?