Method and System for Automated Subdomain Discovery

TR202513183A3Pending Publication Date: 2026-08-21T C ISTANBUL MEDIPOL UNIVERSITESI
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
TR202513183
Authority / Receiving Office
TR · TR
Patent Type
Applications
Current Assignee / Owner
Filing Date
2025-09-12
Publication Date
2026-08-21

Smart Images

  • Figure 00000018_0000
    Figure 00000018_0000
  • Figure 00000019_0000
    Figure 00000019_0000
Patent Text Reader

Abstract

This invention refers to an automated subdomain discovery management method applicable to digital infrastructures, particularly where continuous monitoring and accurate identification of subdomains are required to ensure security and efficiency. This invention also describes a system that utilizes this method.
Need to check novelty before this filing date? Find Prior Art

Description

1 TARIFF METHODS AND SYSTEMS FOR AUTOMATIC SUBFIELD DISCOVERY Technical Area 5 The invention relates to a subdomain discovery and management method, and also includes OSINT, DNS roughing. bruteforce, web crawling, and blurring / permutation techniques It involves an automated system that integrates various components. Previous Technique In the field of digital infrastructure, the exploration and management of sub-domains is playing an increasingly important role. Examples of such applications include penetration testing, vulnerability assessment, and Continuous monitoring of large-scale corporate networks can be provided. Accurate identification 15 The need is playing an increasingly important role. “Where and when is a subfield "Where and when was it modified or removed?", "Which This clarifies questions such as "Which subfields are actively used and which are unnecessary?" These questions should be clarified by examining the data collected during the exploration process. It needs to be validated and enriched with additional information. Currently, this involves signatures, DNS 20. manual verification of records or, for example, manual correlation of results This is done through the use of fragmented tools that require this. This is especially true because networks are dynamic. It becomes problematic when it evolves and existing tools cannot adapt quickly. It is coming. Subdomain lists based on predefined word lists and DNS queries. Subdomain scanning tools that identify these are known. Tools like Sublist3r and Knockpy. It operates in this way. However, these tools only provide static exploration and This usually requires manual updating of word lists. The results are incomplete and It frequently contains false positives. 30 Web scraping techniques were also used to identify subdomains from the website content. These methods extract data from HTML, JavaScript, or metadata. With this... Together, they are inefficient for large-scale operations and often require manual adjustments. 2 They require this. The results are largely dependent on frequently changing website structures. And this reduces reliability. Exploration frameworks like Recon-ng, including subfield data, are publicly available. It is known to gather information from multiple sources. These frameworks involve collecting data in 5 ways. While centralizing the process, it provides raw, unprocessed results that require additional manual analysis. Lack of automated validation or visualization makes practical subfield management difficult. It reduces their effectiveness. Patent document US20200125800A1 covers general 10 aspects, including some aspects of subdomain exploration. It describes a method for collecting and analyzing web content. However, the method... It does not integrate multiple complementary exploration techniques and does not include automated validation or It does not provide comprehensive reporting. Patent document US10977458B2 partially highlights 15 vulnerabilities related to the subdomain. It describes a real-time cybersecurity monitoring system. However, the system, An end-to-end workflow for automated discovery, validation, and reporting of subdomains. It does not offer. Patent document US20220122050A1, web 20 including subdomain elements It describes the automated monitoring and reporting of assets. However, in general It focuses on web assets and includes OSINT, DNS brute force, and network scanning. (crawling) and blurring / permutation techniques, as well as advanced filtering. It lacks a specific integration of its mechanisms. Additionally, in the cybersecurity sector, there are subdomain discovery tools such as Amass, Subfinder, and OWASP ZAP. Commercial tools and open-source projects that provide partial solutions are known. However... Together, these remain fragmented, require expert knowledge to configure, and It lacks unified integration, automated validation, or dynamic monitoring capabilities. In conclusion, all the problems mentioned above necessitate an innovation in the relevant field. It made it necessary. Purpose of the Invention 3 This invention is designed to provide end-to-end, real-time visibility across digital infrastructures. OSINT, DNS brute force, web crawling, and Preprocessing with blurring / permutation, validation and filtering (DNS / SSL), dynamic Automated subfield discovery and management integrating monitoring and visualization / reporting 5 It is related to the method and system. Another objective of the invention is seamless integration with third-party cybersecurity platforms. enabling the reuse of validated configurations and word lists. 10 that support and facilitate continuous improvement through feedback-driven updates The goal is to provide a modular, scalable, and interoperable architecture. Brief Description of the Invention All the objectives mentioned above and those that will emerge from the detailed explanation below are 15 The present invention enables the creation of a computer for automated subdomain discovery and management. It is an applied method. Accordingly, innovation is initiated by user input into the workflow; Inputs including target areas, scan parameters and uploaded external files By sending, user interaction is carried out and an authentication and user Validating roles and credentials through the database; user logins 20 by cleaning, validating and formatting, removing duplicates, domain names and by validating rules and reusing inputs through a browser and configuration Preprocessing data by storing it in the database; discovery resources from the scanner and OSINT, DNS roughing, retrieved from the configuration database and producing raw results. 25 including bruteforce, web crawling and blurring / permutation Subdomain discovery is performed using multiple techniques, including DNS queries and Confirming the validity of subdomains discovered through SSL checks, if incorrect. Remove positives and process and track results in a database. Validation and monitoring to transmit updates to a dynamic monitoring database while storing them. Applying filtering; adding, modifying or deleting subfields 30 monitoring, dynamically adding data provided by external APIs or the user to the monitoring database. to integrate and enrich sub-domain exploration for continuous improvement of data. Dynamic monitoring is performed to send the processed data back to validation modules. and validated subdomain data from the monitoring database in charts, graphs or 4 By presenting reports in the form of downloadable reports, it allows for interactive filtering and user interpretation. It is the realization of visualization and reporting that enables this. Thus, the invention, Intelligent, automated, and scalable subdomain management in dynamic digital infrastructures. It also enables management. Furthermore, it provides integrated multi-technical scanning, adaptive monitoring, and By combining it with enriched reporting, it increases operational efficiency, manual 5 It reduces effort and develops proactive security strategies. In one application of the invention, the method involves authentication during the user interaction step. and validating user roles and access permissions through the user database Therefore, the invention provides secure role-based access control, preventing unauthorized access. This prevents irregularities and ensures the reliability of the sub-area exploration and management process. It strengthens [the system]. In addition, it provides adaptive permission management for different user categories. It provides and fulfills both managerial and standard roles within the system. It supports. In one application of the invention, the method uses a scanner and a scanner during the data preprocessing step. Reusable configurations in the configuration database, validated It involves the storage of word lists and specific rules. Therefore, the invention is valid. efficient reuse of selected inputs in multiple scanning processes By doing so, it reduces repetitive installations and minimizes configuration errors. Furthermore, without revalidation in future exploration missions. workflow by allowing the permanent storage of user-defined settings that can be applied. It improves its efficiency and scalability. In an application of the invention, the method involves subfield exploration to maximize the scope of discovery. 25 During this step, OSINT, DNS brute force, web crawling, and Integration of multiple scanning techniques, including blurring / permutation. It involves combining the strengths of different discovery approaches. Therefore, the invention combines the strengths of different discovery approaches. by combining them to provide a comprehensive definition of both static and dynamic subdomains. It provides. In addition, it reduces false negatives, increases accuracy, and 30 eliminating the need for modular tools or manual integration of separate techniques It provides a unified workflow. One application of the invention is the method to ensure accuracy and explain why general search DNS settings are used. DNS during the validation and filtering step to eliminate false positives. It involves the implementation of queries and SSL certificate checks. Therefore, the invention, by ensuring that only valid and operational subfields are retained in the final dataset. It increases the reliability of the discovery results. Additionally, it filters out erroneous inputs. 5 This improves reliability and the accuracy of subsequent monitoring and reporting processes. It strengthens. In one application of the invention, the method involves dynamic monitoring of historical data and external intelligence. It includes integration into the database and continuous monitoring of sub-domain environments. 10 Therefore, the invention is timely incorporating newly added, modified, or removed subfields. This ensures that the monitoring process remains up-to-date and reliable by enabling its detection. Furthermore, it enhances situational awareness by enriching monitoring results with third-party intelligence. It improves and enhances proactive risk management for evolving digital infrastructures. In one application of the invention, the method generates graphs, heat maps, and diagrams for subdomain relationships. Interactive visualizations and downloadable reports, including hierarchical structures. It involves creating. Therefore, the invention results in an intuitive and user-friendly way. By presenting it in this way, it simplifies the interpretation of complex subdomain data. Furthermore, 20 allows users to customize report formats according to their operational needs. By enabling the application of interactive filters, it improves decision-making and governance. In another configuration of the invention, it is defined for automated subdomain discovery and management. An automated subdomain discovery system that includes tools to perform all transaction steps, and A management system is provided. Thus, the invention provides a system architecture compatible with the method. 25 It enables its practical implementation within. In addition, functional modules, data by enabling their foundations and user interfaces to work in a coordinated manner a unified platform for the exploration, validation, monitoring and reporting of fields It provides. In another configuration of the invention, the system allows users to adjust their configuration settings. They can send, upload files, monitor scan progress, and see the results. It includes a user interface that enables them to obtain, the user interface, target areas defining, selecting scan depth, OSINT, DNS brute force, network scanning 6 Enable and validate modules such as (web crawling) and blurring / permutation. a configuration settings module for storing configured settings in a static database and external rules including domain lists, word lists or subdomain creation rules. retrieving datasets, verifying their formats, removing duplicates, and validating them. It includes a file upload module for storing entries for reuse. 5 Therefore, the system is intuitive and facilitates the preparation and monitoring of reconnaissance missions. It provides a structured interaction layer. In addition, it reduces the effort of manual installation. by reducing and providing reusable configurations for subsequent processes It improves operational efficiency. In another configuration of the invention, the system will clean, validate, and... It includes a preprocessing module configured to standardize, preprocessing The module is a data preprocessor for duplicate removal, domain standardization, and error handling. Verify the structural and logical correctness of the component and inputs, and report errors. to create and store reusable validated data 15 It includes a validation component. Therefore, the system accepts all data provided by the user. This ensures that the inputs are consistent, error-free, and compatible with subsequent exploration processes. Additional by preventing erroneous configurations and validating data across multiple processes. By enabling its reuse, it improves overall reliability and efficiency. In another configuration of the invention, the system includes passive DNS, SSL / TLS certificates, and search. The engines also include an OSINT scanner for retrieving data from public repositories and open sources. a browser that uses multiple techniques to define subdomains, including and The discovery module generates candidate sub-domains from keyword lists and includes general search filtering. A DNS brute-force scanner is used to query DNS servers, subdomain 25 HTML, JavaScript, metadata, and helper files are used to extract this information. a web crawling scanner and predefined patterns to analyze and to create subdomain variations using user-defined rules It includes a blurring / permutation scanner. Therefore, the system is static, dynamic, and It provides comprehensive exploration coverage in unconventional subfields. In addition, 30 By integrating multiple scanning methods within a unified and automated framework, it prevents errors. It reduces negatives and improves accuracy. 7 In another configuration of the invention, the system tracks changes in sub-domains and discovers a data integration and monitoring module that enriches the results, addition, modification or compares current scan results with historical data to detect deletions monitoring unit and external integrating API-based or user-provided intelligence It includes a data input unit. Therefore, the system continuously and dynamically processes sub-domain environments. 5 This allows for monitoring. In addition, internal discovery is combined with external intelligence sources. By doing so, it improves situational awareness and proactive safety. In another configuration of the invention, the system verifies DNS and SSL validity, A validation and filtering process to remove duplicates and exclude false positives. 10 To maintain the unit and validated data, identify trends and anomalies, and produce reports. a results processing and storage module that includes a storage and analysis unit for generating Therefore, the system ensures the accuracy and reliability of the discovery results. In addition, it supports long-term informed decision-making and proactive risk management. It provides long-term analytical capabilities. 15 In another configuration of the invention, the system provides graphs, heat maps, and other representations for sub-domain structures. It will create hierarchical diagrams and enable interactive filtering of validated results. It will enable users to download reports in multiple formats, and Storing preferences for iterative optimization through surveys or ratings 20 a visualization and feedback configured to collect user feedback It includes a notification module. Therefore, the system presents complex information through intuitive visualization. It simplifies the interpretation of discovery results. In addition, it is feedback-oriented. By integrating improvements into the overall workflow, adaptability and user satisfaction are enhanced. is developing. 25 In another configuration of the invention, the system stores user credentials, roles, and sessions. an authentication database for managing data, reusable a static database for configurations, validated word lists and rules, raw A scanner database for storing scan results, 30 validated and analyzed. a processed data database, history and API to protect subdomain data. a monitoring and external data database for enhanced intelligence and feedback and user including a feedback and user data database to collect preferences It includes interconnected databases. Therefore, the system contains all operational information. 8 structured data that supports secure, reliable and efficient management. It creates a management architecture. In addition, different modules within the platform and Ensuring scalability and integration by providing seamless interaction between databases. It improves. In another configuration of the invention, when executed by a computer, the computer's This causes the automated subdomain discovery and management method to perform its steps. A computer program containing instructions is provided. Therefore, the invention relates to the method. This enables its implementation in a flexible and portable software format. In addition, the existing By allowing integration into security infrastructures and deployment across different platforms, it enables various 10 It ensures compatibility with computing environments. In another configuration of the invention, the computer program is stored on it. a computer-readable data carrier is provided. Therefore, the invention, a robust and portable version for running the program on different computing devices It ensures that the software is stored in this way. In addition, the software can be used in various operational environments. safe distribution, easy distribution and reliable protection It makes things easier. Description of the Forms of the Invention The figures and relevant explanations necessary for a better understanding of the invention are given below. It has been given. Figure 1 shows the flowchart of the method. Figure 2 shows a schematic representation of the system. Descriptions of the Elements / Parts / Components Constituting the Invention To better explain the device developed with this invention, the parts and 30 shown in the figures are... The sections are numbered, and the corresponding numbers are given below. 9 Method for automated subdomain discovery and management. 100 Initiating the workflow 102 Implementing user interaction 104 Executing data preprocessing 106 Sub-field exploration carried out 108 Implementation of Validation and Filtering 110 Implementing dynamic monitoring 112. Performing visualization and reporting. Automated subdomain discovery and management system 200 User interfaces 202 Configuration settings module 204 File upload module 210 Preprocessing module 212 Data preprocessing component 214 Data validation component 220 Scanner and discovery module 222 OSint (open source intelligence) scanner 224 DNS brute-force scanner 226 Web crawling browsers 228 Blurring / permutation scanner 230 Data integration and monitoring module 232 Monitoring units 234 External data input unit 240 Result processing and storage module 242 Validation and filtering unit 244 Storage and analysis units 250 Visualization and feedback modules 260 Interconnected databases 261 Authentication databases 262 Static database 263 Browser database 264 Processed data database 265 Monitoring and external data database 266 Feedback and user database 270 Data carriers Detailed Description of the Invention This detailed explanation is intended solely to facilitate understanding of the subject and Automatic subdomain discovery using examples that do not aim to impose any limitations 5 It describes the method and system for this. Figure 1 shows a schematic representation of the method. A computer-based method. It provides automatic subdomain discovery and management (10). As shown in Figure 1, the invention The method includes the following steps: 10 ● Starting the workflow with user login (100); ● Including target areas, scanning parameters, and uploaded external files. by submitting entries and through an authentication and user database, roles and Performing user interaction by validating identity information (102); 15 ● By cleaning, validating, and formatting user inputs, duplicates by removing, validating domain names and rules, and making entries reusable. Pre-processing data by storing it in the browser and configuration database. (104); ● Discovery sources are retrieved from the scanner and configuration database, and raw 20 The results were generated using OSINT, DNS brute force, and web crawling. and subtract using multiple techniques including blurring / permutation the field exploration was carried out (106); ● Verifying the accuracy of subdomains discovered through DNS queries and SSL checks. Confirm, remove false positives and dynamically monitor updates 25 11 When transmitting to the database, the validated results are processed and stored in the monitoring database. Implementation of validation and filtration for storage (108); ● Monitoring the addition, modification, or deletion of subdomains, via external APIs or to integrate user-provided data into a dynamic monitoring database and 5 sub-domain exploration and validation modules for continuous improvement of enriched data. Dynamic tracking is performed to send back (110); and ● Charts and graphs of processed and validated subdomain data from the monitoring database. or by presenting them as downloadable reports, enabling interactive filtering and user interaction. Visualization and reporting that allows interpretation (112). The method also incorporates advanced techniques that improve operational efficiency and scalability. It includes. During the user interaction step (102), in order to provide secure access. Roles and access permissions are validated through authentication and user database. During the data preprocessing step (104), reusable configurations are created. Validated word lists and specific rules will be used by the scanner and 15 for future scans. The configuration is stored in the database. In an application of the invention, the sub-domain is explored. step (106), OSINT, DNS to maximize coverage and reduce false negatives Brute force, web crawling, and blurring / permutation. It integrates in parallel. In addition, in the validation and filtering step (108), To ensure accuracy and eliminate false positives caused by general search DNS, 20 DNS queries and SSL certificate checks are implemented. In addition, monitoring step (110) Integrate historical data and external intelligence to continuously enrich discovery results. Finally, in the visualization and reporting step (112), the sub-field relationships Interactive graphs, heat maps, and for user-friendly interpretation. Hierarchical structures are being created. 25 Figure 2 shows a schematic representation of the system. The processing steps of the method are shown. an automated subdomain discovery and management system (20) which includes tools for implementation The system is provided with user interface (200), preprocessing module (210), scanner and discovery. module (220), data integration and monitoring module (230), results processing and storage 30 module (240), visualization and feedback module (250) and interconnected databases It is designed to interact with (260). 12 User interface (200), allows users to submit configuration settings, files It allows them to upload files, monitor scan progress, and retrieve results. This includes the following: ● Defining target areas, scanning depth, OSINT, DNS brute force 5 modules such as bruteforce, web crawling and blurring / permutation for enabling and storing validated settings in a static database configuration settings module (202); and ● External rules including field lists, word lists, or subfield creation rules retrieving datasets, validating their formats, removing duplicates, and creating validated 10 A file upload module for storing entries for reuse (204). Preprocessing Module (210) will clean, validate and standardize the inputs. It is configured. It includes the following: ● Data preprocessing for duplicate removal, domain name standardization, and error management. component (212); and 15 ● To verify the structural and logical accuracy of inputs, generate error reports, and a data validation component for storing reusable validated data (214). Scanner and discovery module (220), multiple techniques for identifying sub-areas It uses the following: 20 ● Passive DNS, SSL / TLS certificates, search engines, public pools, and other open an osint scanner (222) for retrieving data from sources; ● Creating candidate subdomains from keyword lists and DNS with general search filtering. A DNS bruteforce scanner (224) for querying servers; ● HTML, JavaScript, metadata, and helper files for extracting subdomain information 25 a web crawling scanner (226) to analyze; and ● using predefined patterns and user-defined rules to create sub-areas A blurring / permutation browser to generate variations (228). The data integration and monitoring module (230) monitors changes in sub-domains and It enriches the discovery results. It includes the following: 30 ● Existing scan results to detect additions, modifications, or deletions a monitoring unit that compares with past data (232); and ● External data to integrate API-based or user-provided intelligence. input unit (234). 13 The Results Processing and Storage Module (240) includes the following: ● Verify DNS and SSL validity, remove duplicates, and exclude false positives. a validation and filtering unit to keep (242); and ● Maintaining validated data, identifying trends and anomalies, and generating reports. to create a storage and analysis unit (244). 5 The visualization and feedback module (250) provides graphs, heat maps and for sub-domain structures. It will create hierarchical diagrams and enable interactive filtering of validated results. It will enable users to download reports in multiple formats, and User feedback through surveys or ratings for iterative optimization. It is configured to collect notifications. The interconnected databases (260) support the entire system and include the following: It includes: ● A user ID 15 to manage user credentials, roles, and session data. validation database (261); ● for reusable configurations, validated word lists and rules a static database (262); ● a scanner database for storing raw scan results (263); ● A processed data 20 to hold validated and analyzed subdomain data. database (264); ● A tracking and external data system to store history and API-enriched intelligence. database (265); and ● A feedback and user data system to collect feedback and user preferences. database (266). 25 The invention also includes instructions that, when executed, carry out the steps of the method. a computer program and a computer-readable document on which the program is stored It includes data carriers (270), thus providing portability, distribution flexibility and system The software is securely protected. 30

Claims

14 REQUESTS 1. A computer-based method for automatic subdomain discovery and management (10), It is characterized by including the following steps: - Starting the workflow with user login (100); 5 - including target areas, scanning parameters and uploaded external files by submitting entries and roles through an authentication and user database. and performing user interaction by validating identity information (102); - by cleaning, validating, and formatting user inputs, and removing duplicates, by validating domain names and rules and making reusable entries available through a browser and 10 Execution of data preprocessing by storing it in the configuration database (104); - discovery sources are retrieved from the scanner and configuration database and are raw. OSINT, DNS brute force, network scanning, and the results were generated. Subfield using multiple techniques including blurring / permutation the discovery was made (106); 15 - Verifying the accuracy of subdomains discovered through DNS queries and SSL checks. To confirm, remove false positives, and dynamically monitor updates. When transmitting to the database, the validated results are processed and monitored in the database. Implementation of validation and filtration for storage (108); - Monitoring the addition, modification, or deletion of subdomains, via external API or 20 to integrate user-provided data into a dynamic monitoring database and enriched data for continuous improvement of sub-domain exploration and validation modules. Dynamic tracking is performed to send back (110); and - Charts and graphs of processed and validated subdomain data from the monitoring database. or by presenting in the form of downloadable reports, enabling interactive filtering and user-friendly interfaces. 25 Visualization and reporting that allows interpretation (112).

2. Authentication and user database during user interaction step (102) characterized by the validation of user roles and access permissions through this process. The method described is a computer-based method according to Claim 1. 30 3. During the data preprocessing step (104), the scanner and configuration database are re-processed. available configurations, validated word lists, and custom rules A computer-implemented method, as defined in Claim 1, characterized by data storage.

4. To maximize the scope of discovery, OSINT, DNS during subdomain discovery step (106). multiple methods including brute force, network scanning and blurring / permutation Characterized by the integration of scanning techniques, computer according to Claim 1. Practical method. 5 5. Ensuring accuracy and preventing false positives caused by general search DNS. DNS queries and SSL during validation and filtering step (108) to remove computer according to Claim 1, characterized by the application of certificate controls. Practical method. 10 6. Subfields where historical data and external intelligence are integrated into a dynamic monitoring database. The Request is characterized by the continuous monitoring of their environments (110). Computer-based method according to 1.

7. Including graphs, heat maps, and hierarchical structures for subdomain relationships. characterized by the creation of interactive visualizations and downloadable reports (112). The method used is a computer-based approach according to Claim 1.

8. An automated 20-bit system containing tools to perform the processing steps of the method in Claim 1. sub-area discovery and management system (20).

9. According to request 8, the system requires users to submit their configuration settings, files. a user who can upload, monitor scan progress and retrieve results It is characterized by including the interface (200), 25 Here, the user interface includes the following: - target domain definition, depth scanning, OSINT, DNS brute force, networking Enabling and validating modules such as scanning and blurring / permutation. Configuration settings for storing the configured settings in a static database. module (202); and 30 - external, including field lists, word lists, or subfield creation rules. retrieving datasets, validating their formats, removing duplicates, and validating the data. A file upload module for storing entries for reuse (204). 16 10. The system will clean and validate the inputs according to any of the requirements 8-9, and by including a preprocessing module (210) configured to standardize is characterized by, Here, the preprocessing module includes the following: - A data preprocessor for copy removal, domain standardization, and error management 5 component (212); and - verify the structural and logical accuracy of inputs, generate error reports, and a data validation component for storing reusable validated data (214).

11. The system is based on any of claims 8-10, including the following: a scanner and discovery module that uses multiple techniques to define areas (220) It is characterized by its inclusion of: - passive DNS, SSL / TLS certificates, search engines, public repositories, and open sources. an OSINT scanner to retrieve data (222); 15 - Creating candidate subdomains from keyword lists and DNS with general search filtering. a DNS brute force scanner (224) to query its servers; - HTML, JavaScript, metadata, and helper files for extracting subdomain information. a network scanning scanner to analyze (226); and - using predefined patterns and user-defined rules, subfield 20 A blurring / permutation browser to generate variations (228).

12. To detect additions, modifications or deletions by the monitoring unit (232) It compares the current scan results with historical data and the external data input unit. (234) It integrates API-based or user-provided intelligence, sub 25 a data integration that tracks changes in the fields and enriches the discovery results and characterized by including a monitoring module (230) to any of Claims 8-11 according to the system.

13. The system is based on any of the requirements 8-12, and includes a result processing and 30 It is characterized by containing a storage module (240): - To verify DNS and SSL validity, remove duplicates, and rule out false positives. a validation and filtering unit to keep (242); and 17 - Maintaining validated data, identifying trends and anomalies, and generating reports. to create a storage and analysis unit (244).

14. The system shall be in accordance with any of the requirements 8-13 and shall perform the following: 5 by including a configured visualization and feedback module (250) It is characterized by: - Creating graphs, heat maps, and hierarchical diagrams for sub-domain structures; To enable interactive filtering of validated results; - to enable users to download reports in multiple formats; and - will collect user feedback through surveys or ratings, iteratively 10 Storing preferences for optimization.

15. A system according to any of claims 8-14, containing interconnected data, including the following: It is characterized by containing bases (260): - an identity 15 to manage user credentials, roles, and session data. validation database (261); - for reusable configurations, validated word lists and rules a static database (262); - a scanner database for storing raw scan results (263); - a processed data 20 to hold validated and analyzed subdomain data. database (264); - a monitoring and external data database for intelligence enriched with history and API (265); - and to collect feedback and user preferences, a feedback and user data system. database (266).

16. When executed by a computer, the computer must respond to any of Prompts 1-7. a computer containing instructions that enable it to perform the steps of the method according to program.

17. According to claim 16, 30 by the computer on which the computer program is stored. a readable data carrier (270).