
theHarvester
theHarvester is a free open-source OSINT tool that gathers emails, subdomains, hosts and related public data about a domain from many online sources.
0 upvotes · 0 downvotes
- Category
- OSINT & Reconnaissance
- Pricing
- Free
- Platforms
- LinuxmacOSWindows
- Licence
- Open source
- Reviewed
- Last reviewed 1 October 2026
- Links
- GitHub
What it is
theHarvester is a free open-source reconnaissance tool originally created by Christian Martorella and maintained on GitHub (laramies/theHarvester). It aggregates public OSINT sources to collect email addresses, subdomains, hostnames, IPs, URLs and related footprint data for a target domain during authorised early-stage assessments.
What it helps with
- Harvesting emails and names associated with a domain from public search and data sources.
- Enumerating subdomains and hosts via certificate transparency, DNS datasets and similar feeds.
- Combining many passive modules in one CLI run for external attack-surface scouting.
- Optionally enriching results with third-party APIs (for example Shodan) when keys are configured.
- Supporting red team and penetration-test reconnaissance before active scanning.
- Running locally with Python tooling without a commercial licence for the core project.
Who it's for
Penetration testers, bug bounty hunters and defenders who need a free OSINT harvester as a peer to Amass-style discovery, for authorised scoping of an organisation's public footprint.
Worth knowing
theHarvester itself is free and open source. Some modules call third-party services that may require their own free or paid API keys and quotas. Official repository and logo: github.com/laramies/theHarvester. Homepage attribution often points to edge-security.com. Distinct from commercial internet maps such as Shodan or Censys. Authorised OSINT and penetration-test use only; respect source terms of service.