OSINT
theHarvester
Gathers emails, subdomains, hosts, and employee names from public sources.
Authorized testing only. Practice on systems you own, isolated labs, or targets with written permission. Unauthorized access is illegal.
When
Early passive recon on a domain in scope.
How
Point at domain, select data sources, export results for later phases.
Why
Fast bulk OSINT collection from many free sources.
Commands & usage
theHarvester -d example.com -b all
theHarvester -d example.com -b google,bing,linkedin -l 200 -f report
Commands are educational examples. Adapt hosts, paths, and rates to your authorized scope.
Tags
Related in OSINT
Maltego
Graph-based link analysis for people, domains, infrastructure, and relationships.
Recon-ng
Modular recon framework with workspace DB and API-backed modules.
SpiderFoot
Automated OSINT scanner with web UI covering 200+ data sources.
Sherlock
Hunt usernames across hundreds of social sites.
Maigret
Username OSINT tool with report generation across many sites.
holehe
Checks if an email is registered on various sites.