Subdomain Finder

Enumerate subdomains by mining public certificate transparency logs, passive recon with no active scanning.

About this tool

This tool performs passive reconnaissance by querying crt.sh, which indexes public certificate transparency (CT) logs. Every TLS certificate issued by a trusted CA is logged publicly, making CT logs a rich source of subdomain intelligence without sending a single packet to the target. Results only include names that appeared in at least one issued certificate, internal-only hostnames and subdomains that never received a certificate will not appear. This is a read-only, entirely legal lookup against public data.

Related tools