Ross ROSS = Recommend OSS · open-source software intelligence for agents

laramies/theHarvester

E-mails, subdomains and names Harvester - OSINT observed · 2026-08-28

github.com/laramies/theHarvester · homepage · Python observed · 2026-08-28

Health v2 · maintenance only

91/100

  • Activity 99
  • Release rhythm 75
  • Longevity 100

Flags: no_license

How is this computed?

round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-03. Adoption (stars, forks) is never an input.

  • gap_med: 33
  • age_days: 5723
  • days_rel: 91
  • days_push: 7
  • n_releases_24m: 12

Full methodology

Adoption not part of the score

17202 stars · 2563 forks observed · 2026-08-28

What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-29, confidence not recorded

theHarvester is a Python CLI tool that gathers open-source intelligence (emails, subdomains, hostnames, IPs, names, URLs, ASNs) about a domain from search engines, certificate transparency logs, DNS datasets, and other public sources. It includes a REST API and a browser-based workflow (HarvestView), with JSON/JSONL/XML/SQLite output for structured evidence.

Use cases

  • enumerate subdomains of a target domain from passive sources
  • find email addresses associated with a company for a phishing assessment
  • gather reconnaissance data during the early stages of a penetration test
  • collect hostnames and IPs from certificate transparency logs
  • run passive OSINT against a domain before an authorized red team engagement
  • export discovered assets to JSON or SQLite for further analysis

When to choose

  • you need a single tool aggregating many passive OSINT sources for domain reconnaissance
  • you want structured output (JSON, JSONL, SQLite) for evidence retention and integrations
  • you are doing authorized red team or blue team asset discovery

When to avoid

  • you need active scanning or exploitation rather than passive reconnaissance
  • you require guaranteed availability of specific data sources, since providers control their own quotas and formats
  • you lack authorization to test the target domain

Facets

cli-tool · maturity active

osint search-engine web-scraping cli security security osint penetration-testing python cli windows cross-platform reconnaissance subdomain-enumeration email-harvesting red-team threat-intelligence osint command-line linux macos docker

3 sources

Member repositories

RepositoryRoleHealth v2
laramies/theHarvestermain91

For agents

markdown · JSON · MCP: product_card(name="laramies/theHarvester")

Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem