Enumerating Subdomains with crt.sh
There are a lot of tools you can use to see what a company is up to techwise. Dig is good, whois is good, spidering through webapps looking for links and apis is good, but my favorite… really dead simple way of getting information on a domain is to just checkout https://crt.sh. The script To even call this a script is an insult to scripting. I’m just curling the csv endpoint of the crt.sh website and using some cli-foo to turn it into subdomains. ...