VulnScanners Logo

Recon & OSINT

theHarvester

Email, subdomain, and host OSINT gathering.

osintrecon
theharvester — terminal
$ theHarvester -d example.com -b all

What it does

theHarvester collects emails, names, subdomains, IPs, and URLs from public sources like search engines and certificate transparency logs. Useful for early footprinting of a target organization.

Common use cases

  • Build a target employee directory from public email harvests for social engineering.
  • Discover subdomains and IP ranges without ever touching the target's infrastructure.
  • Cross-reference leaked credentials against harvested emails in a password-spray test.

Key features

  • Queries search engines, CT logs, and APIs from a single tool.
  • Harvests emails, subdomains, hosts, and virtual hosts in one pass.
  • Results exportable to HTML, JSON, XML, and plain text formats.

Source

https://github.com/laramies/theHarvester

More Recon & OSINT tools

Need hosted scanning instead of local tooling?

Run a scan in the browser →