I'd recommend checking this tool out if you are conducting some recon to gain an overview of HTTP-based attack surface. According to the Aquatone Github repository,
You can also use it alongside other tools, like Amass, Nmap, Masscan, etc.
Link to the tool: https://github.com/michenriksen/aquatone