Observe
Consume append-only Certificate Transparency logs and licensed historical indexes. Each source observation retains its log identity, index, and timestamp.
CertificateScan is designed to help analysts investigate public infrastructure without disguising inference as fact.
Consume append-only Certificate Transparency logs and licensed historical indexes. Each source observation retains its log identity, index, and timestamp.
Parse X.509 fields into a stable schema and coalesce duplicate precertificate/final-certificate events without discarding provenance.
Create evidence-backed relationships among certificates, SANs, issuers, public keys, and separately observed live endpoints.
On explicit request, perform a standard public TLS handshake. The resulting observation is timestamped and never substituted for passive CT history.
It does not prove the certificate was deployed, trusted by every client, or controlled by the named organization.
DNS, firewalls, geography, rate limits, and transient failures can all prevent a successful connection.
Shared SANs, keys, or endpoints are useful pivots, not automatic proof of common ownership.