Matchboxmatchbox
← Back to match

GSAN (Get Subject Alternative Names)

Extracts subdomains directly from SSL certificate Subject Alternative Names on HTTPS servers.

Desktopfreeglobal

GSAN is a desktop tool that connects to an HTTPS server and extracts Subject Alternative Names from its SSL certificate to reveal subdomains and virtual hosts, including internal or self-signed certificates not present in public logs. Intended for penetration testers, security researchers and bug bounty hunters, it automates SAN discovery and produces structured output for chaining into other reconnaissance tools; it installs via pip/pipx or Docker and accepts targets from files or stdin.

Categories
securityreconnaissance

Full match profile

Behind the summary, Matchbox keeps a richer profile of GSAN (Get Subject Alternative Names) - the signals our matcher actually reads to decide when to surface it. It stays private; claim the listing to see and control it.

  • Problem & pain-point mapping
  • Who we surface it to (audience fit)
  • What it's a strong alternative to
  • Trust & credibility signals

Try Matchbox with your own problem

Describe what is not working - we’ll show you whether GSAN (Get Subject Alternative Names) (or something else) actually fits.