FAQ
Attack Surface Discovery

What is certificate transparency discovery?

Certificate transparency discovery uses public certificate logs to identify domains and subdomains associated with issued TLS certificates. Because certificates may contain names that do not appear in current DNS or asset inventories, the logs can reveal historical, forgotten or newly created infrastructure. A certificate entry does not prove that an asset is active or owned, so it must be validated with other signals. ThingsRecon combines certificate data with DNS, hosting and active observations to improve attribution. In practice, teams should record the supporting evidence, confirm ownership and business criticality, and connect the finding to an accountable workflow. This prevents a useful observation from becoming another isolated score or dashboard alert. The strongest implementation combines external intelligence with internal knowledge, supplier engagement and documented risk decisions, creating a view that remains useful as the digital ecosystem changes.