Skip to main contentSkip to main content
Room Banner
Back to all walkthroughs
Room Icon

Subdomain Enumeration

Premium room

Learn the various ways of discovering subdomains to expand your attack surface of a target.

easy

30 min

194,238

User profile photo.
User profile photo.

To access material, start machines and answer questions login.

Set up your virtual environment

To successfully complete this room, you'll need to set up your virtual environment. This involves starting both your AttackBox (if you're not using your VPN) and Target Machines, ensuring you're equipped with the necessary tools and access to tackle the challenges ahead.
Attacker machine
Status:Off
Lab machine
Status:Off
Subdomain enumeration is the process of finding valid subdomains for a domain, but why do we do this? We do this to expand our attack surface to try and discover more potential points of vulnerability.

We will explore three different subdomain enumeration methods: Brute Force, (Open-Source Intelligence) and Virtual Host.

Start the machine and then move onto the next task.
Answer the questions below
What is a subdomain enumeration method beginning with B?

What is a subdomain enumeration method beginning with O?

What is a subdomain enumeration method beginning with V?