Animated radar sweeping a network and discovering certificates, each host turning from unverified grey to verified teal

Certificate Discovery

You can't manage what you can't see. Scan your network for TLS certificates in use - live endpoints, whole subnets, and IP ranges - and get one de-duplicated inventory of every one, with expiry, issuer, key, and exactly where it's deployed.

Certificate Discovery expands your targets - a single host, a host:port, a CIDR block such as 10.0.0.0/24, or an IP range - into concrete endpoints, performs a real TLS handshake against each (capturing even expired, self-signed, or untrusted certificates), and collapses everything it finds into a single inventory de-duplicated by thumbprint. One certificate deployed across a dozen hosts shows as one row listing all twelve locations. It's the discovery step upstream of Certificate Validator (validate what's found) and Certificate Manager (renew it) - because most expired-certificate outages come from a certificate nobody was tracking.

Screenshot

See it in action

The real app. Click to zoom in, hover the markers to see what each part does.

Certificate Discovery main window showing the targets box, ports field, Scan/Export CSV buttons, and the de-duplicated inventory grid
Click to zoom

Hover a marker for details, or click the screenshot to zoom in.

Certificate Discovery main window, zoomed in
Features

Find every certificate, before it finds you

Hosts, subnets & ranges

Point it at a single host, a host:port, a whole CIDR block such as 10.0.0.0/24, or an IP range - across as many ports as you like. Oversized blocks are guarded so a stray /8 can't run away.

Real TLS capture

Each endpoint gets a real TLS handshake that captures whatever certificate it presents - even expired, self-signed, or untrusted ones - so nothing hides from the inventory.

De-duplicated inventory

Certificates are collapsed by thumbprint: one certificate deployed across a dozen hosts is one row listing all twelve locations - not twelve rows to reconcile by hand.

Expiry at a glance

Every row shows days-to-expiry and an Expired / Expiring / Valid status, plus issuer, key algorithm and size, signature algorithm, and every subject alternative name.

CSV export & history

Export the inventory for reporting, ticketing, or hand-off to renewal - and (on higher tiers) save target lists and keep an inventory history to spot new or changed certificates over time.

Scheduled discovery & headless CLI

Re-scan your estate on a schedule via Windows Task Scheduler, or drive it from your own scripts with CertificateDiscovery.exe --discover ... - a distinct exit code fires when anything is expired or expiring.

Plans & Pricing

Each tier unlocks more

Pick how much automation you need, then choose once-off or monthly billing. Certificate Discovery licenses per machine, not by certificate volume.

One-time payment - yours to keep, no subscription.

Standard

For checking one endpoint at a time.

Single-endpoint discovery - scan one host or host:port - full inventory detail on screen.

Standard+

For scanning a whole estate at once.

Everything in Standard, plus bulk discovery across CIDR blocks and IP ranges, and CSV export.

Advanced

For tracking your estate over time.

Everything in Standard+, plus saved target lists and a persisted inventory history to spot new or changed certificates.

All plans are billed in USD. Prices in other currencies are an approximate conversion for your reference, based on indicative exchange rates - your invoice will be issued in USD.

Standard

Standard covers the core of Certificate Discovery: point it at one host or host:port and see the full inventory detail - issuer, validity dates, key algorithm and size, signature algorithm, SANs, and expiry status. No bulk scanning, export, or automation at this tier, by design.

Best for: Anyone who wants to inspect what a single endpoint is presenting.

Standard+

Standard+ adds bulk discovery - scan whole CIDR blocks and IP ranges across as many ports as you like in one run - plus CSV export of the de-duplicated inventory for reporting or hand-off to renewal. Everything from Standard is included.

Best for: Anyone mapping the certificates across a whole network segment.

Advanced

Advanced adds saved target lists - name and re-use the estate you scan - plus a persisted inventory history, so you can see which certificates are new, changed, or newly-expiring since the last run. Everything from Standard+ is included.

Best for: Teams that track their certificate estate over time, not just once.

Prices shown are a suggested starting point, not final quotes - contact us to confirm your plan.

Interested in Certificate Discovery?

Contact us for current pricing and licensing options.

Contact us