Live Certificate Transparency (crt.sh) Subdomain OSINT Scanner (2026)

Query public RFC 6962 Certificate Transparency logs in real time to discover unique subdomains, wildcard TLS certificates, issuing CAs, and historical staging assets with zero packets sent to the target.

Live Certificate Transparency (crt.sh) Subdomain Recon Scanner — Interactive Console
Runs locally in your browser • Instant output
Ready (Cached CT Snapshot Loaded)
Subdomain / SANCertificate Authority IssuerNot Before
zerosuniverse.comLet's Encrypt E52026-01-15
*.zerosuniverse.comCloudflare Inc ECC CA-32026-02-01
tools.zerosuniverse.comLet's Encrypt R112026-02-19
api.zerosuniverse.comGoogle Trust Services WE12026-01-28
cdn.zerosuniverse.comCloudflare Inc ECC CA-32025-11-10
staging.zerosuniverse.comLet's Encrypt E62025-12-04
Clean Target List & Nmap / httpx Recon Pipeline
$ cat << 'EOF' > subdomains.txt
zerosuniverse.com
tools.zerosuniverse.com
api.zerosuniverse.com
cdn.zerosuniverse.com
staging.zerosuniverse.com
EOF
httpx -l subdomains.txt -silent -status-code -title -tech-detect
nmap -iL subdomains.txt -sV -T4 --top-ports 100 -oN ct_recon.txt
Ready
Embed / Cite This Tool (Markdown & HTML)
GitHub / Reddit Markdown Badge[![Live Certificate Transparency (crt.sh) Subdomain Recon Scanner](https://img.shields.io/badge/ZerosUniverse-Free_Tool-ff6a00)](https://www.zerosuniverse.com/tools/crt-sh-subdomain-recon-scanner/)
Blog / Documentation HTML Citation<a href="https://www.zerosuniverse.com/tools/crt-sh-subdomain-recon-scanner/">Live Certificate Transparency (crt.sh) Subdomain Recon Scanner — ZerosUniverse</a>

2026 Quick-Reference Cheat Sheet & Benchmark Table: Live Certificate Transparency (crt.sh) Subdomain Recon Scanner

Quick Answer & 2026 Technical Summary (crt sh subdomain finder)Updated 2026 Standard

Certificate Transparency (CT) is an internet security standard mandated by Chrome and Apple Safari requiring every publicly trusted Certificate Authority (CA) to append all newly issued TLS/SSL certificates to public, append-only cryptographic Merkle tree logs. Because developers obtain TLS certificates for staging, internal VPN, and API subdomains (via Let's Encrypt or ACM), those hostnames become permanently searchable in CT logs. Use this interactive crt sh subdomain finder above to test certificate transparency subdomain scanner, passive osint subdomain enumeration, and crt.sh json api parser locally in your browser with zero server uploads.

Target Keyword Spec: crt sh subdomain finder | Modules: Live Sectigo crt.sh CT Log Query Engine • SAN Deduplication & Wildcard Separator • High-Value Attack Surface Highlighter
Primary Focus: crt sh subdomain finder
Core Capability: certificate transparency subdomain scanner
Privacy Mode: 100% Client-Side (Zero Upload)
Technical Parameter / ModuleStandard / Keyword SpecArchitecture & Validation RuleOperational Use Case (2026)
Live Sectigo crt.sh CT Log Query Enginecertificate transparency subdomain scannerFetches live X.509 certificate records from public Certificate Transparency...Bug Bounty & Red Team External Attack Surface Mapping
SAN Deduplication & Wildcard Separatorpassive osint subdomain enumerationSplits multi-line `name_value` Subject Alternative Name (SAN) fields, norma...Shadow IT & Unauthorized Certificate Auditing
High-Value Attack Surface Highlightercrt.sh json api parserAutomatically tags interesting dev, staging, api, vpn, admin, git, internal...Subdomain Takeover Reconnaissance
Execution & Privacy Architecture100% Client-Side WebCrypto / JS Sandbox0 Bytes Sent to External ServersSafe for internal SOC & authorized lab artifacts
NIST SP 800-53 / OWASP AlignmentOWASP ASVS v4.0.3 / NIST CSF 2.0Deterministic Rule & Header VerificationMaps findings to actionable hardening controls
Cryptographic & Entropy StandardSHA-256 / AES-256-GCM / Argon2id≥ 128-bit Effective Security MarginMeets 2026 post-quantum & zero-trust baselines
In-Depth ZerosUniverse Tutorial

What is Footprinting & OSINT Reconnaissance in Ethical Hacking?

Read our complete step-by-step editorial guide, architecture breakdown, and defensive best practices on ZerosUniverse.

Read Full Guide

How to Use Live Certificate Transparency (crt.sh) Subdomain Recon Scanner

01

Enter an Apex Domain to Audit

Type a root domain name (e.g., `cloudflare.com`, `hackerone.com`, or your own organization's domain) without `https://`.

02

Run the Passive Certificate Transparency Scan

Click Scan CT Logs to query public certificate issuances and parse all Common Name (CN) and Subject Alternative Name (SAN) entries.

03

Filter by Keyword, Wildcard Status, or Expiry State

Search for high-interest keywords (`api`, `dev`, `staging`, `vpn`) or toggle out wildcard (`*.`) and expired certificates.

04

Copy Deduplicated Hostlist or Recon Pipeline

Copy the clean hostname list directly to your clipboard or download CSV/JSON for downstream probing with `httpx` or `subfinder`.

Key Capabilities & Technical Architecture

Live Sectigo crt.sh CT Log Query Engine

Fetches live X.509 certificate records from public Certificate Transparency logs, automatically falling back to instant curated OSINT datasets if upstream crt.sh PostgreSQL is under heavy load.

SAN Deduplication & Wildcard Separator

Splits multi-line `name_value` Subject Alternative Name (SAN) fields, normalizes casing, strips duplicate renewals, and separates `*.` wildcard certificates from concrete FQDNs.

High-Value Attack Surface Highlighter

Automatically tags interesting dev, staging, api, vpn, admin, git, internal, and pre-prod subdomains alongside Certificate Authority (Let's Encrypt, DigiCert, Cloudflare) breakdowns.

1-Click Export for httpx, Nuclei & Nmap

Export clean newline-delimited hostnames (`subdomains.txt`), JSON intelligence reports, or ready-to-run `httpx` and `nmap -iL` verification pipelines.

Practical Use Cases

Bug Bounty & Red Team External Attack Surface Mapping

Discover forgotten staging servers, internal API gateways, and regional microservices that received a TLS certificate without ever sending a DNS query to the target's authoritative nameservers.

Shadow IT & Unauthorized Certificate Auditing

Audit every public X.509 certificate ever issued for your organization's apex domain and verify compliance with your CAA (Certification Authority Authorization) DNS records.

Subdomain Takeover Reconnaissance

Identify historical subdomains from expired TLS certificates that may still have dangling CNAME records pointing to unclaimed cloud buckets or SaaS instances.

Frequently Asked Questions (FAQs)

What is Certificate Transparency (RFC 6962) and why does it expose subdomains?+

Certificate Transparency (CT) is an internet security standard mandated by Chrome and Apple Safari requiring every publicly trusted Certificate Authority (CA) to append all newly issued TLS/SSL certificates to public, append-only cryptographic Merkle tree logs. Because developers obtain TLS certificates for staging, internal VPN, and API subdomains (via Let's Encrypt or ACM), those hostnames become permanently searchable in CT logs.

Is querying crt.sh considered completely passive reconnaissance?+

Yes. Querying Certificate Transparency logs retrieves public registry metadata from third-party CT log servers (operated by Sectigo, Google, and Cloudflare). Zero packets, DNS requests, or HTTP probes are sent to the target organization's infrastructure.

How can organizations hide internal hostnames from Certificate Transparency logs?+

Avoid requesting individual public certificates for sensitive internal hostnames (`jira-staging.internal.corp.com`). Instead, either issue a public wildcard certificate (`*.internal.corp.com`) so the specific prefix is not logged, or use an internal Private PKI (such as HashiCorp Vault PKI or Active Directory Certificate Services) that does not publish to public CT logs.

Why does crt.sh sometimes return duplicate rows for the same subdomain?+

CT logs record both the Precertificate (submitted by the CA before final signing) and the final Leaf Certificate, as well as every 60-to-90-day automated renewal over several years. Our scanner automatically deduplicates all `name_value` SAN entries into a unique hostname set while preserving the earliest and latest issuance timestamps.

What is a DNS CAA record and how does it relate to CT log monitoring?+

A Certification Authority Authorization (CAA) DNS record specifies which CAs (e.g., `letsencrypt.org` or `digicert.com`) are permitted to issue certificates for your domain. Pairing strict CAA records with regular CT log monitoring ensures no unauthorized CA can issue a rogue certificate for your domain.