certificate_transparency
Search public certificate transparency logs (crt.sh) for certificates issued to a domain in scope. Passive discovery of hostnames; some results may be out of scope.
Instructions
Search public certificate transparency logs (crt.sh) for certificates issued to a domain in scope. Passive: the target is not contacted. IMPORTANT: results routinely include hostnames OUTSIDE your scope. Each is returned with in_scope; those marked false are observations only and every other tool will refuse them. Cost: 1 quota unit, 5-30 seconds (crt.sh is often slow).
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| limit | No | Maximum certificate entries to return. | |
| domain | Yes | Domain name in scope. | |
| include_expired | No | Include expired certificates. |
Output Schema
| Name | Required | Description | Default |
|---|---|---|---|
| domain | Yes | ||
| source | No | crt.sh | |
| entries | No | ||
| warning | No | Hosts listed here were discovered, not authorized. Entries with in_scope=false cannot be passed to any other tool, and the server will refuse them. | |
| truncated | No | ||
| elapsed_ms | No | ||
| total_entries | No | ||
| discovered_hosts | No | ||
| returned_entries | No |