{"id":13843854,"url":"https://github.com/zzzteph/probable_subdomains","last_synced_at":"2025-07-11T20:30:53.964Z","repository":{"id":83622880,"uuid":"582047732","full_name":"zzzteph/probable_subdomains","owner":"zzzteph","description":"Subdomains analysis and generation tool. Reveal the hidden!","archived":false,"fork":false,"pushed_at":"2025-03-08T23:50:47.000Z","size":5126496,"stargazers_count":236,"open_issues_count":0,"forks_count":24,"subscribers_count":6,"default_branch":"main","last_synced_at":"2025-03-09T00:24:09.103Z","etag":null,"topics":["bugbounty","bugbounty-tool","wordlist"],"latest_commit_sha":null,"homepage":"https://weakpass.com/generate/domains","language":null,"has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"gpl-3.0","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/zzzteph.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":null,"funding":null,"license":"LICENSE","code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null,"governance":null,"roadmap":null,"authors":null,"dei":null,"publiccode":null,"codemeta":null}},"created_at":"2022-12-25T13:01:06.000Z","updated_at":"2025-03-08T23:50:53.000Z","dependencies_parsed_at":null,"dependency_job_id":"58ed55c8-d3e1-45d8-91cd-980fa7c4d91c","html_url":"https://github.com/zzzteph/probable_subdomains","commit_stats":null,"previous_names":[],"tags_count":0,"template":false,"template_full_name":null,"purl":"pkg:github/zzzteph/probable_subdomains","repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/zzzteph%2Fprobable_subdomains","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/zzzteph%2Fprobable_subdomains/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/zzzteph%2Fprobable_subdomains/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/zzzteph%2Fprobable_subdomains/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/zzzteph","download_url":"https://codeload.github.com/zzzteph/probable_subdomains/tar.gz/refs/heads/main","sbom_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/zzzteph%2Fprobable_subdomains/sbom","host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":264892027,"owners_count":23679208,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2022-07-04T15:15:14.044Z","host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":["bugbounty","bugbounty-tool","wordlist"],"created_at":"2024-08-04T17:02:29.432Z","updated_at":"2025-07-11T20:30:48.970Z","avatar_url":"https://github.com/zzzteph.png","language":null,"funding_links":[],"categories":["Others"],"sub_categories":[],"readme":"# Probable (sub)domains\n\n\nOnline tool: [https://weakpass.com/generate/domains](https://weakpass.com/generate/domains)\n\n \n\u003cp align=\"center\"\u003e\n  \u003cimg src=\"https://github.com/zzzteph/probable_subdomains/blob/main/generate.gif?raw=true\"\u003e\n\u003c/p\u003e\n\n\n\n## TL;DR\n\n\nDuring bug bounties, penetrations tests, red teams exercises, and other great activities, there is always a room when you need to launch amass, subfinder, sublister, or any other tool to find subdomains you can use to break through - like **test.google.com**, **dev.admin.paypal.com** or **staging.ceo.twitter.com**.\nWithin this repository, you will be able to find out the answers to the following questions:\n\n1. What are the most [popular subdomains](https://github.com/zzzteph/probable_subdomains/tree/main/wordlists/hostnames)?\n2. What are the most [common words](https://github.com/zzzteph/probable_subdomains/tree/main/wordlists/levels) in multilevel subdomains on different levels?\n3. What are the most [used words](https://github.com/zzzteph/probable_subdomains/tree/main/wordlists/words) in subdomains?\n\n\nAnd, of course, [wordlists](https://github.com/zzzteph/probable_subdomains/tree/main/wordlists) for all of the questions above!\n\n\n## Methodology\n\nAs sources, I used lists of subdomains that were collected by [shrewdeye.app](https://shrewdeye.app/), [bounty-targets-data](https://github.com/arkadiyt/bounty-targets-data/) or that just had responsible disclosure programs. If subdomains appear more than in 5-10 **different** scopes, they will be put in a certain list. For example, if **dev.stg** appears both in **\\*.google.com** and **\\*.twitter.com**, it will have a frequency of 2. It does not matter how often **dev.stg** appears in **\\*.google.com**. That's all - **nothing more, nothing less**.\n\n\n\n\n\n\n\n## Lists\n\n\n### Subdomains\n\nIn these lists, you will find the most popular subdomains **as is**. 100,1000,10k,100k,1m - are the most popular subdomains sorted by their frequency. \n\n- [subdomains.txt.7z](https://shrewdeye.app/files/subdomains.txt.7z)\n- [subdomains_100.txt](https://raw.githubusercontent.com/zzzteph/probable_subdomains/main/wordlists/hostnames/subdomains_100.txt) \n- [subdomains_1000.txt](https://raw.githubusercontent.com/zzzteph/probable_subdomains/main/wordlists/hostnames/subdomains_1000.txt) \n- [subdomains_10k.txt](https://raw.githubusercontent.com/zzzteph/probable_subdomains/main/wordlists/hostnames/subdomains_10k.txt) \n- [subdomains_100k.txt](https://raw.githubusercontent.com/zzzteph/probable_subdomains/main/wordlists/hostnames/subdomains_100k.txt)\n- [subdomains_1m.txt](https://raw.githubusercontent.com/zzzteph/probable_subdomains/main/wordlists/hostnames/subdomains_1m.txt)\n\n\n### Subdomain levels\n\nYou will find the most popular words from subdomains split by levels in these lists. F.E - **dev.stg** subdomain will be split into two words **dev** and **stg**. **dev** will have level = 2, **stg** - level = 1. You can use these wordlists for combinatory attacks for subdomain searches. \n\n\n- [level_1.txt.7z](https://shrewdeye.app/files/levels/level_1.txt.7z)\n- [level_2.txt.7z](https://shrewdeye.app/files/levels/level_2.txt.7z)\n- [level_3.txt.7z](https://shrewdeye.app/files/levels/level_3.txt.7z)\n- [level_4.txt.7z](https://shrewdeye.app/files/levels/level_4.txt.7z)\n- [level_5.txt.7z](https://shrewdeye.app/files/levels/level_5.txt.7z)\n- [level_1_100.txt](https://raw.githubusercontent.com/zzzteph/probable_subdomains/main/wordlists/levels/level_1_100.txt)\n- [level_1_1000.txt](https://raw.githubusercontent.com/zzzteph/probable_subdomains/main/wordlists/levels/level_1_1000.txt)\n- [level_2_100.txt](https://raw.githubusercontent.com/zzzteph/probable_subdomains/main/wordlists/levels/level_2_100.txt)\n- [level_2_1000.txt](https://raw.githubusercontent.com/zzzteph/probable_subdomains/main/wordlists/levels/level_2_1000.txt)\n- [level_3_100.txt](https://raw.githubusercontent.com/zzzteph/probable_subdomains/main/wordlists/levels/level_3_100.txt)\n- [level_3_1000.txt](https://raw.githubusercontent.com/zzzteph/probable_subdomains/main/wordlists/levels/level_3_1000.txt)\n- [level_4_100.txt](https://raw.githubusercontent.com/zzzteph/probable_subdomains/main/wordlists/levels/level_4_100.txt)\n- [level_4_1000.txt](https://raw.githubusercontent.com/zzzteph/probable_subdomains/main/wordlists/levels/level_4_1000.txt)\n- [level_5_100.txt](https://raw.githubusercontent.com/zzzteph/probable_subdomains/main/wordlists/levels/level_5_100.txt)\n- [level_5_1000.txt](https://raw.githubusercontent.com/zzzteph/probable_subdomains/main/wordlists/levels/level_5_1000.txt)\n\n\n### Popular subdomain words\n\n\nYou will find the most popular words from subdomains on all levels in these lists. For example - **dev.stg** subdomain will be splitted in two words **dev** and **stg**. \n\n\n- [words.txt.7z](https://shrewdeye.app/files/words.txt.7z)\n- [words_100.txt](https://raw.githubusercontent.com/zzzteph/probable_subdomains/blob/main/wordlists/words/words_100.txt)\n- [words_1000.txt](https://raw.githubusercontent.com/zzzteph/probable_subdomains/blob/main/wordlists/words/words_1000.txt)\n- [words_10000.txt](https://raw.githubusercontent.com/zzzteph/probable_subdomains/blob/main/wordlists/words/words_10000.txt)\n\n\n\n\n\n\n## Attributions\n\n- [shrewdeye.app](https://shrewdeye.app) \n- [berzerk0](https://github.com/berzerk0) for the inspiration with the great work [Probable-Wordlists](https://github.com/berzerk0/Probable-Wordlists)\n- [chaos.projectdiscovery.io](https://chaos.projectdiscovery.io/)\n- [bounty-targets-data/](https://github.com/arkadiyt/bounty-targets-data/)\n- Based on some previous iteration of the same idea - https://github.com/zzzteph/substats\n\n\n\n## Thanks!\n\n\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fzzzteph%2Fprobable_subdomains","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Fzzzteph%2Fprobable_subdomains","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fzzzteph%2Fprobable_subdomains/lists"}