domaindrift
Retired — functionality merged into urlrecon.
retired 2026-05-31This tool has moved
domaindrift was a Python CLI for historical subdomain inventory
and subdomain-takeover detection. Both subcommands are now part
of urlrecon as the
domaindrift subcommand — with several improvements:
- Free-source-only enumeration — historical subdomains pulled from Certificate Transparency (crt.sh) and the Wayback Machine CDX API. No DNSDB / SecurityTrails keys needed.
- ~46 takeover fingerprints — curated from
can-i-take-over-xyz(AWS S3, GitHub Pages, Heroku, Azure App Service / CloudApp / Traffic Manager, Fastly, Shopify, Webflow, Ghost, Zendesk, Netlify, Kinsta, …). - Conservative match logic — body marker AND CNAME-suffix gate must both fire before a finding is emitted (the Python build was body-only and prone to false positives).
- NS-hijack heuristic — flags subdomains delegated to known parked nameservers (Sedo, NameBright, ParkingCrew, …).
- Concurrent takeover probes via a tokio semaphore (
--concurrency N). - First-seen / last-seen dates per subdomain (sourced from CT issuance timestamps), so operators can spot recently-issued shadow infrastructure.
- Operator pivot URLs — crt.sh, Wayback Machine, Censys.
- Markdown report output ready for IR write-ups.
Migration
# Old (domaindrift)
curl -fsSL https://cli.johlem.net/install.sh | bash -s -- domaindrift
domaindrift enum cyberramen.com
domaindrift takeover cyberramen.com
domaindrift history cyberramen.com
# New (urlrecon domaindrift)
curl -fsSL https://cli.johlem.net/install.sh | bash -s -- urlrecon
urlrecon domaindrift history cyberramen.com --limit 200
urlrecon domaindrift history cyberramen.com --include-expired --format json
urlrecon domaindrift takeover cyberramen.com --concurrency 16
urlrecon domaindrift takeover cyberramen.com --format markdown
Why retired?
domaindrift duplicated urlrecon's DNS resolver, HTTP client, and
crt.sh client. Folding the two subcommands into urlrecon means
the certificate-transparency code path is shared with
urlrecon certchain, and operators install one
binary instead of two.
Deferred for a follow-up session: the old
monitor subcommand (long-running daemon to alert on
new CT issuances) was not ported — it fits a systemd timer
/ cron job better than a one-shot CLI. DNSSEC validation and
zone-transfer (AXFR) attempts are also deferred; the new
pipeline is OSINT-only, no authoritative-server probing.