A penetration tester wants to query Certificate Transparency logs to find all SSL/TLS certificates issued for a target domain, which may reveal subdomains. Which tool or website is specifically designed for this purpose?
crt.sh is a dedicated Certificate Transparency (CT) log search engine that aggregates and indexes certificates from multiple CT logs, allowing rapid lookups by domain, issuer, or serial number. It directly queries the CT framework's public, append-only logs via a web interface and API, making it the precise tool for checking which certificates have been issued for a domain, including your own. This is why it is the correct answer.
Why this answer
crt.sh is a website that queries Certificate Transparency logs and returns certificates for a domain, often revealing subdomains. Shodan and Censys also provide certificate data but crt.sh is focused on CT logs. Let's Encrypt is a CA, not a log query tool.