search_crt
Enumerate subdomains from certificate transparency logs to discover internal and staging hosts that do not resolve publicly.
Instructions
Enumerate subdomains from certificate transparency logs via crt.sh. Keyless and purely passive (public CA logs), surfaces internal/staging hosts that never resolve publicly. Authorized use only: your own assets or a target you are authorized to assess. Passive, public-source collection.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| domain | Yes | ||
| json_output | No | Return result as structured JSON. |