-
-
Notifications
You must be signed in to change notification settings - Fork 2.6k
Operator Workflows
Start with the smallest source set and least active behavior that can answer the engagement question. Replace example.com only with an authorized target.
uv run theHarvester -d example.com -b crtsh,certspotter,commoncrawlUse the README source matrix to choose complementary sources. Adding every source usually increases noise, rate-limit failures, and runtime more than it improves a focused run.
uv run theHarvester -d example.com -b crtsh,certspotter -f reportUse report.jsonl for automation, provenance, and run interchange. The same command also writes report.json and report.xml compatibility files. See Results and Local Data.
AUTHORIZED_DOMAIN='replace-with-a-domain-you-control'
uv run theHarvester -d "$AUTHORIZED_DOMAIN" -b crtsh,certspotter -rTo control the resolvers used, create a resolver file with one IP address per line and pass its path:
AUTHORIZED_DOMAIN='replace-with-a-domain-you-control'
uv run theHarvester -d "$AUTHORIZED_DOMAIN" -b crtsh -r resolvers.txtDNS requests disclose candidate names to each selected resolver. Candidates from all selected sources are normalized and deduplicated before one run-wide phase queries A, AAAA, and CNAME at most once per hostname and record type. The phase runs at most 20 hostname jobs concurrently with per-query resolver timeouts and no default query-count or phase-runtime ceiling.
Reverse DNS (-n) uses an independent run-wide job set. It deduplicates addresses across overlapping discovered /24 ranges and runs at most 20 PTR jobs concurrently with per-query resolver timeouts and no default request-count or phase-runtime ceiling.
Configure the Shodan key, then enrich resolved hosts:
AUTHORIZED_DOMAIN='replace-with-a-domain-you-control'
uv run theHarvester -d "$AUTHORIZED_DOMAIN" -b crtsh -r -sShodan host enrichment runs after discovery and is separate from the shodan source's subdomain results.
Use only an owned or explicitly authorized target:
AUTHORIZED_DOMAIN='replace-with-a-domain-you-control'
uv run theHarvester -d "$AUTHORIZED_DOMAIN" -cDNS brute force actively tests candidate names. Do not run it against example.com or an unrelated third-party domain.
AUTHORIZED_DOMAIN='replace-with-a-domain-you-control'
uv run theHarvester -d "$AUTHORIZED_DOMAIN" -b crtsh,certspotter -tTreat matches as leads requiring manual confirmation. Do not claim a takeover from a fingerprint match alone.
Install Chromium first, then choose an output directory:
uv run playwright install chromium
AUTHORIZED_DOMAIN='replace-with-a-domain-you-control'
uv run theHarvester -d "$AUTHORIZED_DOMAIN" -b crtsh -r --screenshot screenshotsScreenshots actively open discovered web services and may retain sensitive page content.
AUTHORIZED_DOMAIN='replace-with-a-domain-you-control'
uv run theHarvester -d "$AUTHORIZED_DOMAIN" -aProvide a custom path wordlist with -w FILE. This sends requests directly to the target and must be explicitly in scope.
When a combined run fails, rerun only the affected source with a conservative result limit:
uv run theHarvester -d example.com -b source-name -l 10Check the provider's current status, authentication requirements, rate limits, and terms before reporting a tool defect.
Repository · Releases · Issues · Contributing · Security · License
Reviewed wiki changes belong in docs/wiki/. The live GitHub wiki is the published copy.