1- Nmap scanning to show open ports

nmap -sS -sU -sV -p- subdomain.com

2- Nikto

3- Burpsuite: open the burp then mapping the website and check http history in the burp