Subdomain takeover
A takeover candidate is a name the company still publishes that points at a service they no longer claim. The proof is the unclaimed fingerprint plus ownership of the parent name. Claiming the service is a program decision, not the first step.
Skill
No skill is linked for this class yet. Start with the playbook on this page.
Checklists
None linked for this class yet.
Disclosures
No public card yet.
Playbooks
- Subdomain Takeover - Find dangling DNS records pointing to de-provisioned cloud services you can re-claim.
Tools
- subfinder - Fast passive subdomain enumeration that aggregates 30+ public sources. The default first step of almost every recon workflow.
- httpx - Fast, multi-purpose HTTP toolkit. Probes for live hosts and pulls status, title, tech, CDN, and more. The bridge between recon and scanning.
- nuclei - Template-based vulnerability scanner with thousands of community templates for CVEs, misconfigs, exposures, and takeovers. The workhorse of modern bug bounty.
Questions
A CNAME points at a cloud host. Is that enough?
No. You still need the service-specific unclaimed page, and you need to show the parent name is theirs. A parked marketing page is not a takeover.
Should I register the resource?
Only if the program says a claim is the proof they want, and only a benign marker you can remove. The note can stop at the dangling chain and the fingerprint.
This page is the linked pack hunt_brief("takeover") returns on the MCP connector. Authorized testing only.