Earlier quoted context omitted.
Sorry, let me be more obvious. I am not pointing to a solution, but a pointer to the solution. Showing what is possible. The solution is pulling/parsing the CT logs yourself.
If you’re talking about SSL cert logs, that excludes a ton of web content. And you haven’t shown me that you can even get all those for free anyway
I guess it depends on what you are looking for?
It's far less brute force than trying to randomly generate hostnames and then do lookups, and your solution also misses everything that is just random alphanumeric combinations, of which there are tons.
> And you haven’t shown me that you can even get all those for free anyway
Free? Maybe.