Recon & OSINT
theHarvester
Email, subdomain, and host OSINT gathering.
osintrecon
theharvester — terminal
$ theHarvester -d example.com -b allWhat it does
theHarvester collects emails, names, subdomains, IPs, and URLs from public sources like search engines and certificate transparency logs. Useful for early footprinting of a target organization.
Common use cases
- •Build a target employee directory from public email harvests for social engineering.
- •Discover subdomains and IP ranges without ever touching the target's infrastructure.
- •Cross-reference leaked credentials against harvested emails in a password-spray test.
Key features
- •Queries search engines, CT logs, and APIs from a single tool.
- •Harvests emails, subdomains, hosts, and virtual hosts in one pass.
- •Results exportable to HTML, JSON, XML, and plain text formats.
Source
https://github.com/laramies/theHarvester ↗More Recon & OSINT tools
Need hosted scanning instead of local tooling?
Run a scan in the browser →