About this tool
This tool performs passive reconnaissance by querying crt.sh, which indexes public certificate transparency (CT) logs. Every TLS certificate issued by a trusted CA is logged publicly, making CT logs a rich source of subdomain intelligence without sending a single packet to the target. Results only include names that appeared in at least one issued certificate, internal-only hostnames and subdomains that never received a certificate will not appear. This is a read-only, entirely legal lookup against public data.