1- Nmap scanning to show open ports
nmap -sS -sU -sV -p- subdomain.com
2- Nikto
3- Burpsuite: open the burp then mapping the website and check http history in the burp