Certificate Transparency
Every TLS certificate ever issued for a domain is logged publicly in Certificate Transparency logs. Search them to find subdomains passively — no brute-force, no wordlists, and often stumbles on internal-looking names an attacker or auditor should know about.