theHarvester – Gather E-mail Accounts, Subdomains, Hosts, Employee Names


theHarvester is a tool for gathering e-mail accounts, subdomain names, virtual hosts, open ports/ banners, and employee names from different public sources (search engines, pgp key servers).

theHarvester - Gather E-mail Accounts, Subdomains, Hosts, Employee Names


Is a really simple tool, but very effective for the early stages of a penetration test or just to know the visibility of your company on the Internet.

theHarvester Information Gathering Sources

The sources supported are:

Passive theHarvester Methods

  • google: google search engine
  • googleCSE: google custom search engine
  • google-profiles: google search engine, specific search for Google profiles
  • bing: microsoft search engine
  • bingapi: microsoft search engine, through the API (you need to add your Key)
  • dogpile: Dogpile search engine
  • pgp: pgp key server – mit.edu
  • linkedin: google search engine, specific search for Linkedin users
  • vhost: Bing virtual hosts search
  • twitter: twitter accounts related to an specific domain (uses google search)
  • googleplus: users that works in target company (uses google search)
  • yahoo: Yahoo search engine
  • baidu: Baidu search engine
  • shodan: Shodan Computer search engine, will search for ports and banners

Active theHarvester Methods

  • DNS brute force: this plugin will run a dictionary brute force enumeration
  • DNS reverse lookup: reverse lookup of IPs discovered in order to find hostnames
  • DNS TDL expansion: TLD dictionary brute force enumeration

How to use theHarvester


Searching emails accounts for the domain microsoft.com, it will work with the first 500 google results:

Searching emails accounts for the domain microsoft.com in a PGP server, here it’s not necessary to specify the limit.

Searching for user names that works in the company microsoft, we use google as search engine, so we need to specify the limit of results we want to use:

Searching in all sources at the same time, with a limit of 200 results:

There are some other tools you can check out too like:

snitch – Information Gathering Tool Via Dorks
DMitry – Deepmagic Information Gathering Tool
wig – CMS Identification & Information Gathering Tool

You can download theHarvester here:

theHarvester-2.7.zip

Or read more here.

Posted in: Hacking Tools

, , , , ,


Latest Posts:


Sooty - SOC Analyst All-In-One CLI Tool Sooty – SOC Analyst All-In-One CLI Tool
Sooty is a tool developed with the task of aiding a SOC analyst to automate parts of their workflow and speed up their process.
UBoat - Proof Of Concept PoC HTTP Botnet Project UBoat – Proof Of Concept PoC HTTP Botnet Project
UBoat is a PoC HTTP Botnet designed to replicate a full weaponised commercial botnet like the famous large scale infectors Festi, Grum, Zeus and SpyEye.
LambdaGuard - AWS Lambda Serverless Security Scanner LambdaGuard – AWS Lambda Serverless Security Scanner
LambdaGuard is a tool which allows you to visualise and audit the security of your serverless assets, an open-source AWS Lambda Serverless Security Scanner.
exe2powershell - Convert EXE to BAT Files exe2powershell – Convert EXE to BAT Files
exe2powershell is used to convert EXE to BAT files, the previously well known tool for this was exe2bat, this is a version for modern Windows.
HiddenWall - Create Hidden Kernel Modules HiddenWall – Create Hidden Kernel Modules
HiddenWall is a Linux kernel module generator used to create hidden kernel modules to protect your server from attackers.
Anteater - CI/CD Security Gate Check Framework Anteater – CI/CD Security Gate Check Framework
Anteater is a CI/CD Security Gate Check Framework to prevent the unwanted merging of filenames, binaries, deprecated functions, staging variables and more.


Comments are closed.