Certificate Transparency (CT) is a system of public, append-only logs recording every TLS/SSL certificate issued. Because certificates name the domains they secure, searching CT logs is one of the most effective ways to enumerate an organisation's subdomains and discover infrastructure it has not otherwise advertised.
CT is a favourite of both defenders mapping their own attack surface and investigators mapping someone else's.