Discovery
Freecrt.sh
crt.sh is a free, public search of website security certificates. Every time a web page turns on the little padlock in your browser, that gets logged here, web address and all.
Why it matters
It means companies have basically published a list of their own pages, one entry at a time, every time they secured one. Search a domain and you get pages that aren't linked from any menu.
When to reach for it
First step when you want to map a company's full web presence. It's free, instant, and public.
Worth knowing
Pair it with a quick check of common page names to catch anything that never got its own certificate.
Used in these plays