What is Swampcat?

Swampcat is a certificate transparency intelligence platform that maps hidden infrastructure relationships, detects rogue certificates, and audits TLS configurations — all backed by cryptographic evidence from public CT logs.

How It Works

Ingest

We continuously monitor Certificate Transparency logs from major CAs, indexing every certificate, domain, issuer, and public key into our database in real time.

Analyze

Swampcat builds an evidence-backed relationship graph, mapping domain-to-certificate associations, public key reuse across organizations, and issuer patterns that reveal hidden infrastructure connections.

Expose

Active scanning connects directly to target servers, performing live TLS handshakes to detect weak ciphers, expired certificates, protocol downgrades, and certificates not found in CT logs.

Why Swampcat Exists

Detect Unauthorized Certificates

Rogue or misissued certificates are a real threat. If someone obtains a certificate for your domain without authorization, CT log monitoring is the only way to catch it. Swampcat cross-references live server certificates against CT records to flag discrepancies.

Uncover Shadow IT

Departments and teams often spin up services on subdomains without telling security. Certificates issued for those subdomains show up in CT logs. Swampcat surfaces them and maps them back to your organization's infrastructure graph.

Identify Shared Infrastructure

When multiple domains share a public key or issuer, it reveals infrastructure relationships — shared hosting, CDN configurations, or organizational ties. Swampcat's graph makes these connections visible and auditable.

Audit TLS Posture

Beyond certificate validity, Swampcat's active scanner checks TLS protocol versions and cipher suites. Weak configurations (TLS 1.0, RC4 ciphers) are flagged with an exposure grade so you can prioritize remediation.

Frequently Asked Questions

Ready to explore?

Search any domain to see its certificate history, infrastructure relationships, and TLS exposure grade.