crt.sh
Search certificate-transparency logs for certificates and related hostnames.
- slug
- crtsh
- visibility
- Public
- risk
- safe
- level
- 0
What this tool does.
crt.sh provides direct search access into certificate-transparency data, which makes it valuable for hostname discovery, certificate history and domain footprint research.
Useful for subdomain discovery and investigating public certificate issuance around a target.
Run this tool.
Submit an input and see the runner output here. Execution is server-side and governed by the policy shown in the sidebar.
Everything runs server-side. Inputs and outputs are subject to the tool's policy shown in the sidebar.
Dev-docs · 2 documents.
Related articles.
Start Here: How to Use an OSINT Tool Catalog Without Getting Lost
A practical starting guide to choosing OSINT tools by question, signal family, risk and evidence needs — and using the catalog as a decision system instead of a link directory.
A Practical Method for Domain and Infrastructure Recon
A passive-first, layer-by-layer workflow for domain and infrastructure reconnaissance using DNS, certificate transparency, HTTP behavior, technology signals, historical context and broader internet observations without turning discovery into attribution.
crt.sh vs SecurityTrails vs Censys: Three Different Ways to Read Infrastructure
Compare crt.sh, SecurityTrails and Censys as three different infrastructure evidence layers: certificate history, DNS history and broad current internet-facing asset observations.
Passive First: When Public Web Research Should Stay Narrow
A practical argument for staying narrow and passive as long as possible in public web research, before broader or more interaction-heavy methods start adding noise.
Related tools.
Other tools that share a category with this one.