SubX
SubX is an all-in-one subdomain recon tool written in Go. It discovers subdomains from 5+ sources (crt.sh, VirusTotal, SecurityTrails, AlienVault, Wayback), resolves DNS, detects Cloudflare, scans ports, retrieves SSL/WHOIS/ASN/BGP, and checks hashes against VirusTotal — with a real-time streaming web UI.
0
Stars
0
Forks
0
Watchers
0
Issues
6925
Size (KB)
master
Branch
Files
2 folders · 6 filesClick a file to open it on GitHub. Browse full tree →
README.md
View raw on GitHub →<div align="center">
<h1>SubX</h1>
<p><strong>All-in-one subdomain enumeration & reconnaissance tool</strong></p>
<p>
<img src="https://img.shields.io/badge/Go-1.21%2B-00ADD8?logo=go" />
<img src="https://img.shields.io/badge/license-MIT-blue" />
</p>
<p>
Subdomain discovery · DNS resolution · Cloudflare detection · Port scanning ·<br>
SSL info · WHOIS/ASN/BGP · VirusTotal check · Real-time web UI
</p>
</div>
---
Overview
SubX is a comprehensive subdomain reconnaissance tool written in Go that combines 5 subdomain sources, DNS analysis, network scanning, and threat intelligence into one fast CLI + web tool. It features a real-time streaming web UI powered by Server-Sent Events (SSE) so you can watch scans unfold live in the browser.
Features
Subdomain Enumeration
- crt.sh — Certificate Transparency log search (no API key needed)
- VirusTotal — Subdomain lookup via VirusTotal API
- SecurityTrails — DNS history and subdomain discovery
- AlienVault OTX — Open Threat Exchange pulse indicators
- Wayback Machine — CDX archive subdomain extraction
- Brute Force — DNS brute force with custom wordlist (
-wflag)
DNS & Network
- A record resolution — resolves all discovered subdomains
- NS / MX / TXT — nameserver, mail exchange, and text records
- Reverse DNS (PTR) — IP to hostname lookup
- Cloudflare detection — per-subdomain and network-level proxy detection via IP range matching
- Wildcard filter — detects and removes wildcard DNS entries
- SSL certificate info — issuer, subject, expiry date, days remaining
- WHOIS / ASN — IP geolocation, ISP, AS number, AS name, organization
- BGP prefix / CIDR — IP range and total IP count
- Port scanning — 26 common ports with service and banner detection
VirusTotal Integration
- Check file hashes (SHA-256, MD5)
- Check IP addresses, URLs, and domains
- Shows malicious / suspicious / harmless counts
- Lists individual engine detection results
- Direct permalink to VirusTotal analysis
Web UI
- Real-time streaming logs (SSE) — watch every step as it happens
- Domain scan tab with source selection and port scan toggle
- VT check tab for hash / IP / URL / domain lookup
- API key status badges
- Results displayed with stats grid, network info table, open ports, and subdomains table with Cloudflare badges
Output Formats
- CLI — formatted terminal output with color indicators
- JSON — machine-readable output (
-jsonflag)
- File — save resolved subdomains to file (
-oflag)
Installation
From Source
git clone https://github.com/TEGAR-SRC/SubX.git
cd SubX
go build -o subx.exe .\cmd\subfinder\ # Windows
go build -o subx ./cmd/subfinder/ # Linux / macOS
Pre-built Binaries
Download the latest release from the Releases page.
Quick Start
# Basic scan with VirusTotal + SecurityTrails
subx -d example.com -sources virustotal,securitytrailsFull scan with all sources + port scan
subx -d example.com -scanWeb UI (open http://localhost:8080)
subx -web 8080VirusTotal hash check
subx -check d41d8cd98f00b204e9800998ecf8427eSave results to file
subx -d example.com -o subs.txtJSON output
subx -d example.com -jsonBrute force with wordlist
subx -d example.com -w wordlist.txtCustom thread count and timeout
subx -d example.com -t 20 -timeout 30
API Keys
Create a .env file in the same directory as SubX (auto-loaded):
VT_API_KEY=your_virustotal_api_key
ST_API_KEY=your_securitytrails_api_key
OTX_API_KEY=your_alienvault_otx_api_key
Or set them as environment variables:
# Windows
set VT_API_KEY=your_keyLinux / macOS
export VT_API_KEY=your_key
Where to get API keys
| Key | Source | Sign Up |
|-----|--------|---------|
| VT_API_KEY | VirusTotal | https://www.virustotal.com/gui/my-apikey |
| ST_API_KEY | SecurityTrails | https://securitytrails.com/app/signup |
| OTX_API_KEY | AlienVault OTX | https://otx.alienvault.com/settings |
Usage
CLI Reference
subx -d <domain> [-sources <list>] [-scan] [-w <file>] [-t <n>] [-timeout <s>] [-o <file>] [-json] [-no-wildcard] [-all]subx -web <port>
subx -check <hash|ip|url|domain>
| Flag | Default | Description |
|------|---------|-------------|
| -d | — | Target domain |
| -sources | all | Comma-separated sources: crtsh,alienvault,wayback,virustotal,securitytrails |
| -scan | false | Enable port scanning (26 common ports) |
| -w | — | Wordlist file for DNS brute force |
| -t | 10 | Number of concurrent threads |
| -timeout | 15 | Request timeout in seconds |
| -o | — | Output file for resolved subdomains |
| -json | false | Output results in JSON format |
| -no-wildcard | true | Filter wildcard DNS entries |
| -all | false | Show unresolved subdomains |
| -web | — | Start web UI on specified port |
| -check | — | Check hash, IP, URL, or domain on VirusTotal |
| -show-sources | false | List available sources and exit |
Examples
# Scan with specific sources
subx -d example.com -sources crtsh,alienvault,waybackFull recon with port scan
subx -d example.com -sources virustotal,securitytrails -scan -t 20Brute force subdomains
subx -d example.com -w subdomains.txt -t 50Export results as JSON
subx -d example.com -json -o results.jsonVT check with custom timeout
subx -check 8.8.8.8 -timeout 10Show all subdomains including unresolved
subx -d example.com -all
Web UI
Start the web dashboard:
subx -web 8080
Open http://localhost:8080.
The web UI features:
- Domain Scan tab — enter a domain, select sources, toggle port scan and wildcard filter
- VT Check tab — paste a hash, IP, URL, or domain for VirusTotal analysis
- Real-time logs — watch each step of the scan as it happens (SSE streaming)
- Results — stats grid, network info (IPs, NS, MX, ASN, CIDR, location, SSL), open ports table, and detailed subdomains table with Cloudflare proxy badges
Sources Detail
| Source | Auth | Description |
|--------|------|-------------|
| crtsh | None | Certificate Transparency log via crt.sh |
| alienvault | OTX_API_KEY | AlienVault Open Threat Exchange |
| wayback | None | Internet Archive Wayback Machine CDX |
| virustotal | VT_API_KEY | VirusTotal passive DNS |
| securitytrails | ST_API_KEY | SecurityTrails DNS history |
When -sources all is used, all sources with valid API keys are enabled.
Architecture
cmd/subfinder/main.go — Entry point, CLI flag parsing, .env loader
internal/
├── dns/dns.go — DNS resolution, Cloudflare detection, wildcard filter, NS/MX/TXT/PTR
├── network/network.go — Port scanner, SSL, WHOIS, BGP prefix, service detection
├── runner/runner.go — Orchestrator, source collector, brute force, output, JSON
├── sources/
│ ├── crtsh.go — crt.sh API
│ ├── alienvault.go — AlienVault OTX API
│ ├── wayback.go — Wayback Machine CDX
│ ├── virustotal.go — VirusTotal API (subdomains + hash check)
│ └── securitytrails.go — SecurityTrails API
└── web/server.go — Web UI with SSE streaming
Building
# Build for current platform
go build -o subx .\cmd\subfinder\Cross-compile
$env:GOOS="linux"; $env:GOARCH="amd64"; go build -o subx-linux .\cmd\subfinder\
$env:GOOS="darwin"; $env:GOARCH="amd64"; go build -o subx-macos .\cmd\subfinder\
License
MIT
Repository metadata
- Owner
- TEGAR-SRC
- Primary language
- Go
- License
- Not declared
- Created
- Jul 24, 2026
- Last pushed
- Jul 24, 2026
- Last updated
- Jul 24, 2026
Clone this repository
HTTPS
git clone https://github.com/TEGAR-SRC/SubX.gitSSH
git clone git@github.com:TEGAR-SRC/SubX.gitMore Go repositories
oxrecon
oxrecon is a comprehensive CLI tool that combines DNS, WHOIS, HTTP, SSL/TLS, port scanning, subdomain enumeration, BGP/RPKI analysis, technology detection, and OSINT into a single binary.
terraform-providers
No description
evolution-go
Evolution API / Evolution Go is an open-source WhatsApp integration API
netbird
Connect your devices into a secure WireGuard®-based overlay network with SSO, MFA and granular access controls.