AuditCoreAuditCore
ProPhase 1 · Reconnaissance

Subdomain Takeover Scanner

20 service fingerprints (GitHub, Heroku, S3, etc.). Part of AuditCore's automated security audit pipeline — runs on every scan in the Pro tier and above, with findings normalized into a single severity-rated table.

What is Subdomain Takeover Scanner?

Subdomain Takeover Scanner runs in the Reconnaissance phase of every AuditCore scan that includes it. Discover the target attack surface — subdomains, live hosts, hidden directories, mail config — before any active probing.

Out of the box it covers: 20 service fingerprints (GitHub, Heroku, S3, etc.). Findings are normalized into AuditCore's vulnerability model so they appear next to results from every other scanner — no separate tabs, no tool-specific jargon, one CVSS-rated table.

If you've ever wondered which scanners actually run when you click "Start scan" on AuditCore, this is one of them. The full pipeline is documented per phase, and you can see exactly which tools fired on any given scan from the live terminal feed.

What it tests

Where it runs in the AuditCore pipeline

Phase 1/5 · Reconnaissance
Discover the target attack surface — subdomains, live hosts, hidden directories, mail config — before any active probing.

Source: scanners/subdomain_takeover_scanner.py

Sample findings

Subdomain Takeover Scanner fired on a real target

Typical run produces between 0 and dozens of normalized findings depending on the target's posture. Each finding includes severity, evidence, affected URL/parameter, and a remediation hint.

Available in Pro tier and above

Real vulnerability scanning. Adds ZAP, Nuclei, Nikto, subdomain discovery, JWT analysis, GraphQL introspection, recording proxy. Per-domain license — pay once, rescan unlimited.

Other reconnaissance scanners

FAQ

What does Subdomain Takeover Scanner test for?

20 service fingerprints (GitHub, Heroku, S3, etc.)

Which AuditCore plan includes Subdomain Takeover Scanner?

Available from the Pro plan ($299) and up. Higher tiers also include this scanner — license once, rescan unlimited.

Is Subdomain Takeover Scanner safe to run on production?

Yes — Subdomain Takeover Scanner runs in the Reconnaissance phase, which is non-intrusive. It only reads data the target already exposes (DNS, HTTP responses, public files, headers).

Where does Subdomain Takeover Scanner run in the AuditCore scan pipeline?

Phase 1/5 — Reconnaissance. Discover the target attack surface — subdomains, live hosts, hidden directories, mail config — before any active probing.

Can I rerun Subdomain Takeover Scanner without paying again?

Yes. AuditCore uses a per-domain license model — once you've purchased a tier for a domain, every rescan (manual or scheduled) is included. No metered usage.