Shodan may bring in some false positives since it will show every organization with "Tesla" in its name.
TLDs, Acquisitions & Relations
BugCrowd University diagram
The diagram above displays how to find different brands and top level domains.
The first we can do is find different acquisitions, where we can see whether there is an attack surface that many other people may not have discovered. Keeping an eye on acquisitions is great, but usually acquisitions are not in scope until 6 months after the acquisition.
After that we can look at related domains. This can be related in things like analytics, whois information, dorks, etc.
Acquisitions
Wikipedia
We can search for Tesla.inc on wikipedia and look for subsidiaries.
We can perform a reversewhois with amass and the -d specifyinf the domain we want to search for, and the -whois flag to specify we are doing a reversewhois check.
amass intel -d tesla.com -whois
In green we can see the different domains related to tesla.com.
This wont increase the attack surface, but will show us different places with information about the company and that the company acknowledges as source of information about itself.
Subdomain Enumeration
This tools will return a lot of the same subdomains, so we need to clean the results at the end.