IT Forensics · OSINT

Analysing SSL/TLS certificates using OSINT – utilising certificate data forensically for infrastructure reconnaissance

Publicly accessible SSL/TLS certificate logs contain information on issued certificates, including associated domain names, dates of issue and, in some cases, further technical details.

Enquire without obligation

This data may be useful for identifying other domains associated with a particular infrastructure, even if these are not publicly advertised.

Why LanCologne?

Since its foundation, LanCologne has specialised in professional IT forensics. Our staff have decades of experience in the field of information technology and assist companies, solicitors, private individuals and, on a regular basis, the courts in the technical investigation of complex digital matters.

Our OSINT investigations are always carried out as a complementary component to existing IT forensic, legal or internal corporate enquiries. Every step of the investigation and every piece of digital evidence found is documented and, where technically possible, archived to ensure traceability even if the original online content is subsequently altered or deleted.

Our services

We systematically analyse publicly available certificate logs in order to document the domains associated with a particular infrastructure and how they have evolved over time.

Typical areas of application

Identification of additional domains associated with an infrastructure
Supplementing investigations into phishing and cyber attacks
Reconstruction of the development of technical infrastructure
Support in investigating attacker infrastructure
Judicial and non-judicial expert reports
Collaboration with IT security teams

This is how a certificate analysis works

We search publicly available certificate logs for entries relating to the relevant domain or organisation and document any associated domains found in chronological order.

Why is certificate analysis relevant in a forensic context?

Certificate logs may reveal additional, non-publicly advertised domains belonging to the same infrastructure, which may be relevant to the investigation.

The date on which a certificate was issued can also provide important clues as to when an infrastructure was established.

Frequently Asked Questions

Are certificate logs generally available for public inspection?+
Yes, so-called Certificate Transparency protocols are publicly available and form the basis of this research.
Can this be used to find all of an organisation’s subdomains?+
Not necessarily; only domains with certificates that have been duly issued and logged are recorded.
Is this analysis combined with subdomain enumeration?+
Yes, the two methods often complement each other and are used together to obtain as complete a picture of the infrastructure as possible.

LanCologne – IT Forensics OSINT Cologne

Do you require a professional OSINT investigation into „OSINT-based analysis of SSL/TLS certificates"? LanCologne supports you in the transparent, documented analysis of publicly available digital sources to complement your IT forensic, legal or internal corporate enquiries.

Get in touch now