This returned a very accurate list of subdomains for my target, and I’ve since taken to using wolfram to aid in site enumeration. recon-ng > use api/google_site recon-ng [ google_site ] > set domain example.com DOMAIN > example.com recon-ng [ google_site ] > run [ * ] Searching Google API for : site:example.com ... Use wget on the main page of the target’s domain (usually www.example.com) Parse the results for all subdomains linked to