Try “car wash”, “subscription box”, “Austin” · Esc to close

OSINT Exposed Files Finder

Find exposed files and configurations on domains for security researchers

Developer tool / API SaaS & software Show HN · launch post · ▲ 58

Visit site

search.cerast-intelligence.com

What it does

OSINT Exposed Files Finder searches Certificate Transparency logs for newly discovered domains, then scans them for exposed files and misconfigurations. Users search for domains or domain substrings to see what the tool has already found: environment files (.env), exposed Git directories, configuration files, database dumps, and similar artifacts. Results are stored in a searchable database and presented in read-only format.

Who it is for

The tool targets security researchers, penetration testers, and bug bounty hunters who need to understand what sensitive files and configurations are publicly exposed on domains. It works as a passive reconnaissance resource: users query it to see what has already been discovered rather than running their own active scans.

Pricing

Free for read-only access via the web interface. API keys are also free; users email the creator to request one and describe their intended use.

How it stands out

The service automates continuous monitoring of Certificate Transparency logs—a passive source of domain discovery—and immediately checks new domains for common misconfigurations. This removes the need for users to manually monitor CT logs themselves or run repeated scans. The searchable database format means results are instantly available without running tools. The anti-bot protections (browser challenge, rate limits for unauthenticated users) keep the data usable while discouraging abuse.

What a founder should check

First, verify how many other OSINT tools already index exposed files on domains and how easy those tools are to access. Services like Shodan, Censys, and various open source finders cover similar territory; understanding what unique value a searchable CT-log-based index provides is crucial. Second, examine switching costs for the target audience. If researchers already have workflows built around existing tools or their own scanning infrastructure, the friction to adopt a new search interface may be higher than expected, especially if users need API integration. Third, consider the sustainability moat. The service relies on passive log data that competitors can also access, and the core scanning logic (checking for common files) is not proprietary. Revenue is zero, making long-term operation uncertain unless funding appears.

Thinking of building something like this?

Every launch here is a competitor to somebody's idea. If yours is close, check it against the market before you build: the Full Check names the rivals, the prices and the gaps.

Check an idea like this

More developer tool / api launches

All

Wispbit

Linter that enforces codebase standards with AI coding agents.

Developer tool / API SaaS & softwareShow HN ▲ 31

OnlyJPG

Private browser-based converter for any image format to JPG.

Developer tool / API SaaS & softwareShow HN ▲ 64

Duck-UI

Browser-based SQL IDE for DuckDB running entirely in WebAssembly.

Developer tool / API SaaS & softwareShow HN ▲ 213

Checked ideas in SaaS & software