🕵️
QualityTypeScript

Subdomain Takeover

by CyberStrikeus

Subdomain Takeover is a Quality skill for Claude Code, published by CyberStrikeus in CyberStrike.

1.7K stars269 forkson CyberStrikeus/CyberStrikeAdded 2026/08/12+4% in starsRepository updated 2026/08/12
aiai-agentai-securitybug-bountycybersecuritydevsecopsethical-hackinghackinghacking-toolllmmcpmcp-servermitre-attackoffensive-securityowasppenetration-testingpentestred-teamsecuritysecurity-tools
Install in seconds
Install Subdomain Takeover
Copy Subdomain Takeover into your Claude Code skills folder. Run the command in your terminal, or review the source on GitHub before installing.
terminal
npx degit https://github.com/CyberStrikeus/CyberStrike/tree/main/.cyberstrike/skill/attack-subdomain-takeover ~/.claude/skills/attack-subdomain-takeover

Requires Node.js. Downloads this skill only — not the rest of the repository — into your Claude Code skills folder.

Without Node.js

git clone https://github.com/CyberStrikeus/CyberStrike.git

Clones the whole repository, then copy the skill’s own directory into your skills folder yourself.

In this catalog

Source file
.cyberstrike/skill/attack-subdomain-takeover/SKILL.md in CyberStrikeus/CyberStrike
Installs to
~/.claude/skills/attack-subdomain-takeover
Collection
One of 51 skills cataloged from this repository
Category
Quality1354 skills

What Subdomain Takeover does

Subdomain Takeover identifies dangling CNAME records and fingerprints the cloud services they point to. Use it to check for takeover conditions and verify cloud storage exposure.

Subdomain Takeover is cataloged under Quality on DirSkills. Subdomain Takeover comes from a repository tagged ai, ai-agent, ai-security, bug-bounty and cybersecurity.

Documentation

README

Subdomain Takeover

Objective

Identify subdomains with dangling DNS records (CNAME pointing to unclaimed cloud resources) and claim them to serve attacker content.

Testing Methodology

Phase 1: Subdomain Enumeration

# Passive enumeration
subfinder -d TARGET.com -silent | tee subdomains.txt

# Certificate transparency
curl -s "https://crt.sh/?q=%25.TARGET.com&output=json" | jq -r '.[].name_value' | sort -u >> subdomains.txt

# DNS brute force
puredns bruteforce wordlist.txt TARGET.com -r resolvers.txt >> subdomains.txt

Phase 2: Automated Takeover Check

# Check all subdomains for takeover
attack_script subdomain_takeover subdomains.txt --json-output

This is the opening of the README. Read the full README on GitHub.

Frequently asked about Subdomain Takeover

  • What else does CyberStrikeus publish alongside Subdomain Takeover?

    Subdomain Takeover is one of 51 skills that DirSkills catalogs from CyberStrikeus/CyberStrike, the repository it ships in. Its siblings there include AMI Age Compliance, AMI Encryption Check and AMI Naming Convention Compliance. Each one is a separate skill with its own page in this directory, installs the same way Subdomain Takeover does, and is maintained by CyberStrikeus in that same repository. The rest of the collection is listed on the CyberStrikeus/CyberStrike page.

  • How does Subdomain Takeover compare to other Quality skills?

    Subdomain Takeover ranks #610 by stars among the 1354 Quality skills in this catalog. The most-starred ones next to it are Benchmark, Benchmark Optimization Loop and API Design Patterns. DirSkills ranks by the star count of the repository each skill ships in, so that order reflects how popular those repositories are rather than any review of Subdomain Takeover against them. Open each page to compare what they document and how they install.

More from CyberStrikeus/CyberStrike

Subdomain Takeover is one of 51 skills cataloged on DirSkills from CyberStrikeus/CyberStrike.

See all 51 skills