Keeping a record of domain certificates is an important aspect of maintaining a strong cybersecurity posture and protecting an organization's assets, reputation, and operations against downtime and/or malicious behavior.
Certificates are also important from a compliance perspective. Organizations need to demonstrate due diligence and accountability in the event of a security incident to help protect the company from legal liability and regulatory action.
Search for Certificates
Navigate to Advanced Query Builder > Domain Queries > Certificates.
Specify a domain.
(Optional) Check with_metadata to include metadata.
(Optional) Specify a date in date_min for certificates issued on or after that date.
(Optional) Specify a date in date_max for certificates issued on or before that date.
(Optional) Set a limit to control the number of results.
(Optional) Choose job_id for immediate results or result to wait for longer queries.
(Optional) Enter a domain_regex (valid re2 regex) to override the domain parameter.
(Optional) Specify cert_issuer with wildcards for issuer filtering.
(Optional) Set skip to skip results or max_wait for timeout in seconds.
Click Search.
Save Queries
Organizational users can save queries for future use or sharing.
Specify query parameters.
Click Save Query.
Provide a Name and Description for context.
Click Save. The query appears in Private Queries.
This ensures compliance and detects fake certificates in phishing campaigns.