Certificate discovery

A certificate discovery tool that keeps looking.

A certificate discovery tool answers one question: which certificates exist for my domains? Attack Surface Scan answers it continuously by reading certificate transparency logs every 15 minutes, queuing anything issued by a CA you haven't authorized, adding newly found subdomains to monitoring, and checking which certificates are actually deployed.

No card required to start. Plans from $25/month; first scan in about a minute.

Why SSL certificate inventory goes stale

Certificates get issued without a ticket

A developer runs certbot on a new host, a SaaS vendor provisions a cert for your custom domain, a CDN issues one on your behalf. Every one is public, and few of them reach the inventory spreadsheet.

Surprise issuance is a signal

A certificate from a CA you don't use is either misconfiguration or someone who shouldn't be able to prove control of your name. Either way you want to know the day it is logged.

One-off lookups don't watch

Searching crt.sh gives you a list for the moment you ran it. It doesn't tell you what appears tomorrow, and on large domains the query can be slow or time out.

Issued is not the same as deployed

A renewed certificate that sits in CT logs but never reached the server, or a renewal that stalled, only shows up when you compare the log with what each host serves.

How the certificate discovery tool works

Certificate transparency monitoring, pointed at the domains you have verified, with the results feeding straight into the rest of your monitoring.

CT logs read every 15 minutes

New certificates for your verified domains and their subdomains surface within the quarter hour of being logged, building an SSL certificate inventory that stays current without anyone re-running a search.

Authorized CAs and an unknown-certificate queue

Tell Attack Surface Scan which CAs you use. A certificate from any other issuer lands in an unknown-certificate queue and alerts at once, so surprise issuance gets triaged rather than scrolled past.

Discovered subdomains join monitoring

Names found in CT that resolve are added to monitoring automatically, up to your plan's host limit and with an exclusion list, and get TLS, header, DNS and exposed-service checks like everything else.

Served-certificate probes

Each host's served certificate is checked daily or every six hours by plan, which catches certificates that exist in CT but were never deployed and renewals that stalled partway through.

Certificate discovery vs certificate expiry monitoring

Discovery finds every certificate that exists; expiry monitoring makes sure the ones you serve get renewed. Attack Surface Scan does both, and this page is about the first.

Looking for renewal warnings?

Escalating reminders at 30, 14, 7 and 3 days, stalled-renewal alerts and chain checks are covered on the certificate expiry monitoring page.

Honest limits

Discovery only runs for domains you have verified you own, and CT only covers publicly trusted certificates: private CA and internal certificates never appear there. For a one-off look at any domain, the free attack surface scanner uses the same CT data.

Common questions

What is the best SSL certificate discovery tool?

One that reads certificate transparency continuously rather than on demand, tells you which certificates came from unexpected CAs, and checks what each host actually serves. Attack Surface Scan does all three for verified domains. Cert Spotter is the closest specialist; the comparison lists where each is ahead.

Is there a crt.sh alternative that monitors continuously?

crt.sh is a free, public search of CT logs, useful for a one-off lookup but manual and sometimes slow or unavailable on large domains. Attack Surface Scan reads CT every 15 minutes for your verified domains, alerts on new and unauthorized certificates, and adds discovered subdomains to monitoring.

How do I find the right certificate transparency log monitoring?

Check four things: how often logs are read, whether you can set authorized CAs and triage unexpected ones, whether discovered subdomains are monitored or just listed, and whether the tool checks the certificate each host serves. Attack Surface Scan covers all four from $25/month.

Is this the same as certificate expiry monitoring?

No. Discovery finds every certificate issued for your domains; expiry monitoring warns before the served ones lapse. Both are included, and expiry is covered on the certificate monitoring page.

Find every certificate issued for your domains.

Verify your domain and the CT watch starts with your first scan.

Start your 7-day trial

No card required to start. Cancel any time.