AQUATONE - https://github.com/michenriksen/aquatone
AQUATONE is a set of tools for performing reconnaissance on domain names. It can discover subdomains on a given domain by using open sources as well as the more common subdomain dictionary brute force approach. After subdomain discovery, AQUATONE can then scan the hosts for common web ports and HTTP headers, HTML bodies and screenshots can be gathered and consolidated into a report for easy analysis of the attack surface.
I read an article, couple of weeks ago, about how you can perform a mitm/cyber atack, I think, just by simply register an expired subdomain who wasnt removed from the domain. Unfortunately, I can
t find the article anymore.