Skip to content
Discussion options

You must be logged in to vote

You are correct - the Facebook Certificate Transparency source is dead. Meta discontinued their CT monitoring tool in late 2025.

The source should be removed from subfinder or marked as deprecated. Until then, you can exclude it:

subfinder -d hackerone.com -all -es facebook

The -es flag excludes specific sources.

Alternatively, dont include it in your provider-config.yaml at all.

For CT-based subdomain enumeration, these sources still work well:

  • crtsh (no API key needed)
  • certspotter
  • google (CT logs)

You might want to open an issue to have the Facebook source removed from the codebase since the upstream API no longer exists.

Replies: 2 comments

Comment options

You must be logged in to vote
0 replies
Answer selected by PontusLindblom
Comment options

You must be logged in to vote
0 replies
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
2 participants