Truvo Free Tools
Subdomain finder
Every certificate ever issued for a hostname under your domain is recorded in public Certificate Transparency logs, and that list is often longer than the one your team manages. This finder reads those logs, flags hosts whose names suggest staging or legacy systems, and names the SOC 2 and ISO 27001 controls the result affects.
Ali Aleali, CISSP, CCSP
Co-Founder & Principal Consultant
Former security architect for Bank of Canada and Payments Canada. 20+ years building compliance programs for critical infrastructure. These tools come out of that work.
Connect on LinkedInHow the subdomain finder works
The check is passive: it searches public Certificate Transparency logs for hostnames under your domain and never connects to the hosts it finds.
01
Query
You enter a domain. The tool searches public Certificate Transparency logs, the same open data source researchers and attackers use, for every hostname that has had a certificate issued under it.
02
Read
The result lists the hostnames and flags names that suggest non-production environments: dev, staging, test, qa, uat, internal, admin, old, legacy, beta. A large count is not a failure on its own, but it means the real footprint is probably bigger than the managed one.
03
Map
Each finding names the controls it speaks to: SOC 2 CC3.2, CC6.1 and CC7.1, and ISO 27001:2022 A.5.9 (inventory of information and other associated assets) and A.8.8 (management of technical vulnerabilities). A footprint that matches your asset inventory is evidence; unknown or exposed non-production hosts are a gap to close.
Found a gap? We fix it for you.
Truvo's security engineers inventory and harden your external footprint, and hand you the evidence an auditor asks for. Tell us the domain and we will scope the fix.
-
Asset inventory
-
Decommission legacy hosts
-
Staging behind VPN
-
Patch and monitor
-
Audit evidence
-
Fixed-price scope
Subdomain finder: frequently asked questions
It shows the hostnames under your domain that appear in public Certificate Transparency logs, which record every TLS certificate issued by a trusted authority. If a host ever had a certificate, it is in the list, whether or not it is still running. This tool also flags names that suggest development, staging or legacy systems.
Truvo maps footprint findings to SOC 2 CC3.2, CC6.1 and CC7.1, and to ISO 27001:2022 Annex A controls A.5.9 (inventory of information and other associated assets) and A.8.8 (management of technical vulnerabilities). Exposed non-production hosts additionally map to CC6.6 and A.8.31. The mapping is advisory: it shows which control a finding gives evidence for or signals a gap against. It is not a substitute for an audit.
Yes. The tool reads public log data about certificates that were already issued. It does not connect to, scan or probe any of the hosts it lists.
Hosts nobody manages tend to run outdated software, lack monitoring and sit outside the patch cycle, which makes them a common entry point. Staging hosts add weaker authentication, verbose errors and debug tooling while being reachable from the whole internet. The fix is to inventory the list, decommission what you no longer need, and put non-production environments behind authentication or a VPN.
Not by itself. A large count means your attack surface is probably bigger than the one your team actively manages, and it gives an auditor a simple test of your asset inventory: does every host on the list have an owner, a patch status and a reason to exist.
More free tools
Run the full domain scan or check the configuration of the hosts you found. See all free tools.
Domain security scan
Scan any domain for SPF, DMARC, DNS, TLS, security headers and subdomains in one pass. Graded A to F, each finding mapped to the SOC 2 and ISO 27001 control it supports.
HTTP security headers checker
Check CSP, X-Frame-Options, X-Content-Type-Options, Referrer-Policy and Permissions-Policy on any site.
DNS lookup and hygiene check
Query A, MX, TXT, CAA and nameserver records, check DNSSEC, and see nameserver redundancy.