Cerast Intelligence

Cerast Intelligence

A free search engine for security researchers that scans the public web for exposed .env files, open .git folders, and other misconfigured files on any domain.

🔗 Visit Cerast Intelligence
📁 Security & Privacy🗣️ English📅 July 25, 2026

Description

Companies leak sensitive files by accident all the time: a forgotten .env with API keys, a .git folder left publicly browsable, a database dump sitting in a web root. Cerast Intelligence continuously scans the internet for these mistakes as new domains appear (via certificate transparency logs, the public record every HTTPS certificate gets logged to) and lets anyone search a domain name to see what's been found exposed on it.

Cerast Intelligence is a free OSINT reconnaissance tool built for pentesters, bug bounty hunters, and security teams doing domain reconnaissance. It monitors certificate transparency logs to detect newly-registered domains, then checks each one for commonly-exposed files (.env, open .git directories, config files, database dumps) and indexes anything found into a searchable database. Search is case-insensitive substring matching (minimum 3 characters), gated by browser-based anti-bot verification; an optional free API key (requires an email request describing your use case) removes that friction and raises rate limits. The service is read-only, collects minimal data on searches (search term, result count, timestamp, IP, user-agent), doesn't use tracking cookies, and auto-deletes collected data after a maximum of 180 days. No team, funding, or launch-date information is published, so treat it as an independent researcher's tool rather than a funded company.

💬 Our review

The short version: for pentesters and bug bounty hunters doing domain recon, this is a genuinely useful free shortcut, it does passively and continuously what you'd otherwise have to run your own CT-log-monitoring scanner to get, but there's no team or track record behind it, so don't feed it anything sensitive.

Compared to running your own tool like the open-source ct-exposer (which discovers subdomains via certificate transparency logs, a similar underlying data source), Cerast Intelligence's advantage is that it's already running continuously and indexed, so you get results instantly with a search instead of standing up and maintaining your own scanner. Compared to paid recon platforms like Shodan or SecurityTrails, it's obviously more limited in scope (just exposed-file detection, not full attack-surface mapping), but the price (free) and simplicity are hard to beat for this one specific use case. The honest caveat: there's no visible company, team, or funding behind this, minimal data retention policies are self-reported rather than audited, and as with any third-party OSINT tool, don't rely on it as your only exposure-detection method for anything you're responsible for protecting — verify findings independently.

💰 Pricing

GratuitRecherche web gratuite, clé API gratuite sur demande
Web search GratuitAPI access Gratuit sur demande

📊 Global score

45Average
🌐Availability15/100Faible

1 language · 0 platform

📄Profile75/100Bien

Profile completeness

🤖 AI-enriched data

💰 Pricing model
🆓 Gratuit

Recherche gratuite et illimitée ; clé API optionnelle (aussi gratuite, sur demande avec cas d'usage) pour lever les limites de taux

👥 Target audiencePentesters, chasseurs de bug bounty, équipes sécurité faisant de la reconnaissance de domaine
🗣️ Languagesen
🌍 Target countriesMarché anglophone/international, pas de ciblage géographique visible
👍

Pros

Entièrement gratuit, y compris l'accès API

Scan continu via les logs de transparence de certificats, pas besoin d'infra à maintenir

Rétention de données minimale et limitée à 180 jours

Aucun cookie de tracking

👎

Cons

Aucune entreprise, équipe ou financement visible

Politique de rétention auto-déclarée, non auditée

Portée limitée aux fichiers exposés, pas une cartographie complète de surface d'attaque

Vérification anti-bot peut ralentir l'usage occasionnel

❓ Frequently asked questions

What is Cerast Intelligence in one sentence?
How much does it cost?
Who is it for?
How does it find exposed files?
Does it store my search data?
Is it worth the money compared to alternatives?
Which tool should you pick for your case?