Sign inSign up

salaheldinaz/crtsh

By salaheldinaz

•Updated over 4 years ago

Queries crt.sh for all certs linked to a target domain and return as a list of subdomains.

Image
0

518

salaheldinaz/crtsh repository overview

⁠CRTSH Script

  • The script takes a domain as an argument and queries crt.sh for all certs linked to that domain. Subdomains are parsed out and returned as a list.
  • The script removes duplicate entries, wildcard entries (since they do not indicate that any particular subdomain exists), and the annoying <BR> tags that other tools leave in.

IMPORTANT: the script will also remove subdomains that are not associated to the originally queried domain. This is to reduce noise generated by certs used on shared hosting. The downside is that if an org has multiple different domains referenced in the same cert, these will be stripped out too.

⁠Installation
pip install -r requirements.txt
⁠Usage
⁠python script
python main.py -k example.com
⁠docker
docker build -t "crtsh:latest" . 
docker run -it --rm -v `pwd`:/tmp/ crtsh:latest -k example.com
⁠Options

-k string search keyword/domain. ex.: example

-m string matching parameters. (will be updated later)

-e bool exclude expired certificates. default: true

-o string path to where save the output file. ex.: /result.txt

Tag summary

Content type

Image

Digest

Size

46.1 MB

Last updated

over 4 years ago

docker pull salaheldinaz/crtsh