Generate a wordlist from a list of already discovered subdomains, by splitting each one on its
. labels. Feed it subdomains you already found (e.g. from
Roots, subfinder, amass, etc.) and it prints the
individual words that make them up — useful as a permutation/bruteforce wordlist for finding
more subdomains.
go install -v github.com/kenjoe41/goSubsWordlist@latestgoSubsWordlist reads subdomains from stdin, one per line, and prints words to stdout:
cat subdomains.txt | goSubsWordlist > words.txtFor dev.api.example.com, it prints dev and api — the labels below the registered domain.
The registered domain (example.com) is skipped by default; pass -iR to include it too:
cat subdomains.txt | goSubsWordlist -iR > words.txt| Flag | Default | Description |
|---|---|---|
-iR |
false |
Include the root domain's own label in output. |
-silent |
false |
Suppress the startup banner. |
Output is deduplication-free and unsorted by design — pipe through sort -u if you need a
unique, sorted wordlist:
cat subdomains.txt | goSubsWordlist | sort -u > words.txt-top Nflag: output only theNmost frequently occurring words (e.g.-top 1000). Requires in-memory word-occurrence tracking, which may not scale well for very large subdomain lists — needs benchmarking before landing.