> ## Documentation Index
> Fetch the complete documentation index at: https://docs.snapsec.co/llms.txt
> Use this file to discover all available pages before exploring further.

# Subdomains

> Discover, analyze, and investigate subdomains with deep visibility into DNS, SSL, ports, vulnerabilities, and asset relationships.

## Overview

The **Subdomains** module provides a complete, enriched inventory of all discovered subdomains across your organization.

It goes beyond simple discovery by combining **reachability, vulnerabilities, DNS intelligence, SSL data, open ports, and asset relationships** into a single investigation workflow.

<Frame caption="Subdomain inventory with reachability, vulnerabilities, ownership, and associations">
  <img src="https://mintcdn.com/snapsec-23724fa2/GVhnR0N6y9RNbw6N/images/aim/subdomains1.png?fit=max&auto=format&n=GVhnR0N6y9RNbw6N&q=85&s=8a180e3c441b296ae86196168c02ff4e" width="1911" height="923" data-path="images/aim/subdomains1.png" />
</Frame>

***

## Dashboard View

The dashboard provides high-level visibility into subdomain posture across the organization.

<Frame caption="Subdomain dashboard with vulnerability distribution, environment spread, WAF coverage, and status codes">
  <img src="https://mintcdn.com/snapsec-23724fa2/GVhnR0N6y9RNbw6N/images/aim/subdomains2.png?fit=max&auto=format&n=GVhnR0N6y9RNbw6N&q=85&s=96bf7cf60e600bfd1974ba1e03c0f8f1" width="1675" height="816" data-path="images/aim/subdomains2.png" />
</Frame>

### Key Metrics

* **Total Subdomains** — All discovered assets
* **Live Subdomains** — Actively reachable endpoints
* **Vulnerable Subdomains** — Subdomains with findings
* **Critical Subdomains** — High severity assets

### Visual Insights

* **Vulnerability Distribution** — Severity-based breakdown
* **Environment Distribution** — Production, Staging, Unknown
* **Network Scope** — External vs internal exposure
* **WAF Distribution** — Protected vs unprotected assets
* **Active vs Inactive** — Live vs dead endpoints
* **Status Code Distribution** — HTTP response patterns

***

## Inventory View

The inventory is the **operational layer** for filtering and triaging subdomains.

### Key Columns

| Column              | Description            |
| ------------------- | ---------------------- |
| **Asset Value**     | Subdomain name + title |
| **Status**          | HTTP response code     |
| **Vulnerabilities** | Count of findings      |
| **Reachability**    | External / internal    |
| **Environment**     | Production / staging   |
| **Owner**           | Assigned user          |
| **Associations**    | Linked assets          |
| **Detected On**     | First & last seen      |

### Filters

* **Is Vulnerable**
* **Status Code**
* **WAF Protection**
* **Externally Reachable**
* **Environment**

***

## Subdomain Asset View

Clicking a subdomain opens a **deep inspection view**.

<Frame caption="Subdomain asset overview with general information and metadata">
  <img src="https://mintcdn.com/snapsec-23724fa2/GVhnR0N6y9RNbw6N/images/aim/inside-subdomain3.png?fit=max&auto=format&n=GVhnR0N6y9RNbw6N&q=85&s=090e2501fd7f1839ad432d14a221d932" width="1672" height="870" data-path="images/aim/inside-subdomain3.png" />
</Frame>

### General Information

* **Asset ID**
* **Type (Subdomain)**
* **Domain Value**
* **Environment**
* **Internal Asset**
* **Is New**
* **Associated Assets**
* **First / Last Detected**

***

## Subdomain Details

This section provides live HTTP and infrastructure insights.

<Frame caption="Subdomain details including status, reachability, WAF detection, and server info">
  <img src="https://mintcdn.com/snapsec-23724fa2/GVhnR0N6y9RNbw6N/images/aim/inside-subdomain4.png?fit=max&auto=format&n=GVhnR0N6y9RNbw6N&q=85&s=4cc79dd195aa06c331682fb599d7dcb3" width="1658" height="805" data-path="images/aim/inside-subdomain4.png" />
</Frame>

### Includes

* **Status Code** (e.g., 200, 403)
* **Page Title**
* **Live Status**
* **Externally Reachable (Yes/No)**
* **Network Scope**
* **WAF Detection**
* **Server Type (e.g., nginx)**
* **Content Type**

***

## Security Overview

<Frame caption="Security summary showing vulnerability counts, CVSS, and remediation progress">
  <img src="https://mintcdn.com/snapsec-23724fa2/GVhnR0N6y9RNbw6N/images/aim/inside-subdomain5.png?fit=max&auto=format&n=GVhnR0N6y9RNbw6N&q=85&s=3b0300e3f82d26eeaac6fa25642050c4" width="1653" height="872" data-path="images/aim/inside-subdomain5.png" />
</Frame>

### Security Data

* **Total Vulnerabilities**
* **Severity Breakdown** (Critical, High, Medium, Low, Info)
* **Open vs Closed Vulnerabilities**
* **Aggregate CVSS Score**
* **Remediation Progress**
* **Test Status**
* **Last Scan Date**

***

## Open Ports

<Frame caption="Open ports detected on the subdomain with associated assets">
  <img src="https://mintcdn.com/snapsec-23724fa2/GVhnR0N6y9RNbw6N/images/aim/inside-subdomain6.png?fit=max&auto=format&n=GVhnR0N6y9RNbw6N&q=85&s=18de0ed54c0d8e41dfaa9b09ac2f71f5" width="1661" height="868" data-path="images/aim/inside-subdomain6.png" />
</Frame>

### Port Intelligence

* **Port Number** (e.g., 80, 443)
* **Environment**
* **Vulnerability Status**
* **Associated Assets Count**
* **Last Checked Timestamp**

***

## DNS Records & SSL Certificates

<Frame caption="DNS records and SSL certificates associated with the subdomain">
  <img src="https://mintlify.s3.us-west-1.amazonaws.com/snapsec-23724fa2/images/aim/subdomains-dns-ssl.png" />
</Frame>

### DNS Visibility

* **Record Values (IP / NS / MX / TXT)**
* **Record Type**
* **Resolved From**
* **Third-party indication**
* **Last Checked**

### SSL Certificate Data

* **Common Name**
* **Issuer**
* **Validity Period**
* **Alternative Names**

***

## Asset Relationships

Subdomains are automatically linked to related infrastructure.

### Includes Relationships With:

* **DNS Records**
* **IP Addresses**
* **Repositories**
* **Applications**
* **Other assets in AIM**

This enables teams to **trace dependencies and understand blast radius**.

***

## Data Sources (Adapters)

Subdomain data is enriched through multiple integrations:

* **HackerTarget** — External reconnaissance data
* **CRT (Certificate Transparency)** — Subdomain discovery via cert logs
* **SnapSec ASM** — External attack surface intelligence
* **Vulnerability Management** — Security findings

***

## Why This Matters

The Subdomains module enables teams to:

* Discover **complete external attack surface**
* Identify **publicly exposed assets instantly**
* Correlate **DNS, SSL, and infrastructure signals**
* Detect **open ports and reachable services**
* Track **vulnerabilities with remediation context**
* Understand **asset relationships and dependencies**

This turns subdomain tracking from simple inventory into **full attack surface intelligence**.

***

## Explore Live Demo

<Card title="Explore AIM Live — No Signup Needed" icon="wand-magic-sparkles" href="https://suite.snapsec.co/demo">
  Instantly explore how Snapsec AIM discovers, enriches, and analyzes subdomains in real time — all without creating an account.
</Card>
