> For the complete documentation index, see [llms.txt](https://davidtancredi.gitbook.io/pentesting-notes/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://davidtancredi.gitbook.io/pentesting-notes/r3dcl1ff/webapp-pentest/attack-surface-recon/hednsextractor.md).

# Hednsextractor

A suite for hunting suspicious targets, expose domains and phishing discovery

<pre><code><strong>
</strong><strong>#install
</strong><strong>go install -v github.com/HuntDownProject/hednsextractor/cmd/hednsextractor@latest
</strong><strong>
</strong><strong>#usage
</strong><strong>
</strong>Getting the IP Addresses used for nasa.gov, and enumerating only the networks.

nslookup nasa.gov | awk '/Address: / {print $2}' | hednsextractor -silent -only-networks
<strong>
</strong><strong>---
</strong><strong>
</strong>Getting the IP Addresses used for nasa.gov, and enumerating only the domains
<strong>
</strong>nslookup nasa.gov | awk '/Address: / {print $2}' | hednsextractor -silent -only-domains | tail -n 10
<strong>
</strong><strong>---
</strong><strong>
</strong><strong>Pipe into httpx
</strong><strong>
</strong>nslookup nasa.gov | awk '/Address: / {print $2}' | hednsextractor -silent -only-domains | httpx -mc 200 -title -ip -td
<strong>
</strong><strong>
</strong><strong>---
</strong><strong>
</strong><strong>Hunt for file exposures en masse (in this case, git config file, modify path accordingly)
</strong>
hednsextractor -target nasa.gov -silent | httpx -path /.git/config mc -200 -silent
<strong>
</strong><strong>
</strong></code></pre>
