Matt and GitHub
1e9efc6118
feat: add JSMON passive subdomain discovery ( #2605 )
...
* Add JSMON passive subdomain discovery source
* docs: complete JSMON setup and credential readiness
* fix: read JSMON credentials only from api-keys.yaml
2026-09-09 14:12:07 -04:00
Matt and GitHub
3b01d7f172
feat: clarify saved-run reporting before 5.0 ( #2599 )
...
Provide harvest-report targets, contributions, and hostname-changes with consistent saved-evidence terminology across the CLI, REST API, and HarvestView. Preserve target scope, source-outcome handling, JSONL, and the stored evidence schema.
Update onboarding and operator documentation, keep the domain glossary in CONTEXT.md, record behavior rules in docs/architecture.md, and consolidate release preparation in CONTRIBUTING.md.
Validation: all eight GitHub checks passed at ed54542a; focused reporting and documentation checks passed. Tracks https://github.com/NotoriousRebel/theHarvester/issues/349 .
2026-09-07 16:48:20 -04:00
Matt and GitHub
8a6875ccf2
fix: package license and guard schedule controls ( #2598 )
...
* docs: refresh readme architecture diagrams
* fix: ship release licenses and local UI assets
* fix: fail closed when schedule prerequisites fail
* docs: refresh release-facing operator guide
* fix: keep HarvestView on pinned CDN assets
* docs: apply HarvestView theme to architecture diagrams
* docs: simplify README and clarify diagram labels
2026-09-04 18:20:21 -04:00
NotoriousRebel
240e56efe5
Polish source yield documentation
2026-08-24 16:06:57 -04:00
NotoriousRebel
c3ec07b593
Clarify partial source outcomes
2026-08-23 18:00:26 -04:00
NotoriousRebel
5c74e1a03d
Allow uncapped discovery and report source yield
2026-08-23 17:24:08 -04:00
NotoriousRebel
2c6c5bff4a
refactor: use SQLAlchemy for HarvestView schedules
2026-08-20 16:01:55 -04:00
NotoriousRebel
a1d794d5af
feat: add persistent HarvestView scheduling
2026-08-20 01:21:09 -04:00
NotoriousRebel
1063318c70
Make Baidu browser support optional
2026-08-18 11:25:30 -04:00
NotoriousRebel
a301c0c859
Fix Baidu direct search transport
2026-08-18 11:03:07 -04:00
NotoriousRebel
b37f413c77
docs: simplify source matrix and JSONL example
2026-08-17 01:03:25 -04:00
NotoriousRebel
d0c6583c64
docs: make source matrix easier to scan
2026-08-17 00:26:22 -04:00
NotoriousRebel
4c35f1c54f
docs: make README diagrams readable
2026-08-17 00:19:56 -04:00
NotoriousRebel
b14e564c89
docs: link discovery sources to providers
2026-08-16 21:02:37 -04:00
NotoriousRebel
2c847b84a2
Require Python 3.14
2026-08-16 19:40:13 -04:00
NotoriousRebel
8cfd6cf7bb
docs: refocus README on current usage
2026-08-16 15:02:44 -04:00
NotoriousRebel
c91456531c
feat: export completed runs as SQLite
2026-08-16 14:41:19 -04:00
NotoriousRebel
60ad04ee16
Document JSONL route extraction
2026-08-16 14:07:36 -04:00
NotoriousRebel
5dcc5ecd25
Remove duplicate diagram HTML
2026-08-16 13:55:45 -04:00
NotoriousRebel
edeb440f6b
Expand README architecture diagrams
2026-08-16 13:38:19 -04:00
NotoriousRebel
bc30f6b82d
Restore live package version table
2026-08-16 13:22:47 -04:00
NotoriousRebel
ab931d1da5
docs: correct evidence architecture diagram
2026-08-16 12:53:03 -04:00
NotoriousRebel
03bb10abfc
docs: make JSONL the primary workflow
2026-08-16 11:50:38 -04:00
Matt and GitHub
01f5561284
Merge pull request #2545 from NotoriousRebel/codex/upstream-takeover-evidence
...
Replace takeover fingerprints with typed DNS-first evidence
2026-08-15 11:52:11 -04:00
NotoriousRebel
4bcf2ceae9
fix: restore conservative source-worker default
2026-08-15 11:41:06 -04:00
NotoriousRebel
ea9dab4b87
feat: replace takeover fingerprints with typed evidence
2026-08-15 03:30:33 -04:00
Matt and GitHub
f44807a046
refactor: run discovery sources with TaskGroup ( #2544 )
...
* refactor: run discovery sources with TaskGroup
* fix: preserve source runner compatibility diagnostics
* feat: add configurable source workers
2026-08-15 01:48:33 -04:00
Matt and GitHub
1a9b114a5d
fix: complete DNS enumeration by default ( #2542 )
...
* fix: complete DNS enumeration by default
* test: avoid URL substring sanitizer alert
2026-08-14 22:54:25 -04:00
Matt and GitHub
b8a8f7c7ca
fix: move Shodan discovery into adapter ( #2535 )
...
* fix: move Shodan discovery into adapter (#283 )
* docs: clarify Shodan transport and persistence
* fix: query every Shodan-resolved IPv4
* fix: call Shodan Host API directly
* fix: serve HarvestView assets locally
* Revert "fix: serve HarvestView assets locally"
This reverts commit 413e8b25ab .
* docs: clarify Shodan proxy transport
* docs: clarify Shodan changelog entry
* feat: persist structured Shodan host evidence
* feat: expand Shodan discovery with TLS search
2026-08-14 21:11:12 -04:00
Matt and GitHub
7c4420150d
Add route-aware no-host result filtering ( #2534 )
2026-08-13 11:14:55 -04:00
Matt and GitHub
624066a3e8
Add RouteViews enrichment and sourced ASN organization attribution ( #2528 )
...
* Add RouteViews network enrichment
* Add authenticated RouteViews API access
* Restrict RouteViews to explicit network pivots
* Restore discovered ASN RouteViews enrichment
* Retain sourced ASN organization attribution
* Avoid dangling and repeated ASN attributions
* Keep automatic RouteViews evidence target-relevant
* Complete target-relevant RouteViews enrichment
* Clarify automatic RouteViews IP pivots
2026-08-13 10:46:54 -04:00
Matt and GitHub
1db27309dd
Remove duplicate Chaos discovery source ( #2533 )
2026-08-12 18:47:34 -04:00
Matt and GitHub
aed50e0b0d
Add crt.name composite hostname discovery ( #2531 )
2026-08-12 17:05:12 -04:00
Matt and GitHub
38524ab674
Add Sourcegraph hostname candidates from indexed code ( #2524 )
...
* feat: add bounded Sourcegraph discovery
Use the documented anonymous streaming API with explicit keyword, result, timeout, and line-match bounds; retain only scoped hostname and email evidence with truthful source outcomes.
* Harden Sourcegraph hostname discovery
* Raise Sourcegraph recall budget to 5000
* docs: clarify Sourcegraph candidate semantics
* test: account for combined source catalog
2026-08-12 12:14:02 -04:00
Matt and GitHub
91ed6c1d9f
Add APIs.guru hostname, email, and URL discovery ( #2525 )
...
* feat: add bounded APIs.guru discovery
* docs: clarify APIs.guru result boundaries
2026-08-12 12:06:04 -04:00
Matt and GitHub
801460f835
Fix passive provider failure attribution and parsing ( #2518 )
...
* fix: harden passive provider reliability
* fix: restore HackerTarget reverse DNS coverage
2026-08-11 17:04:11 -04:00
Matt and GitHub
fa8afa5e46
Add bounded virtual-host discovery ( #2517 )
...
* Add bounded virtual-host discovery
* Document virtual host probe boundary
2026-08-11 00:43:04 -04:00
Matt and GitHub
d766c7c59a
Package HarvestView for local deployment ( #2513 )
...
* feat: package HarvestView for local deployment
* Align container smoke with JSONL API
* Align container smoke with unversioned JSONL
* refactor: rename web launcher to harvestview
2026-08-10 00:19:00 -04:00
Matt and GitHub
0d2ab5a0b3
Add the HarvestView web application ( #2512 )
...
* feat: add HarvestView operator UI
* Use JSONL-only HarvestView file flows
* Drive HarvestView activities from the API catalog
* Add result action controls
* Render shared DNS resolver defaults
* Clarify resolver cardinality in HarvestView
* Load Tabulator from CDNjs
* Fix HarvestView wiki link
* Align HarvestView with execution status contract
* Add HarvestView import and action controls
* Harden HarvestView browser assertions
* Simplify HarvestView run selection
* Show truthful HarvestView execution outcomes
* refactor: show canonical URL results in HarvestView
* Show canonical hostname results in HarvestView
* test(harvestview): remove browser error race
2026-08-10 00:08:05 -04:00
Matt and GitHub
1fd5749e52
Add an authenticated durable run API v1 ( #2511 )
...
* Model active evidence in result persistence
* Expose active action diagnostics
* Persist truthful DNS action evidence
* Persist direct action evidence
* feat: add authenticated durable run API v1
* Make API file interchange JSONL-only
* Harden API evidence boundaries
* Remove API rate limiter
* Unify API runs with result persistence
* Support target action runs
* Keep DNS resolver selection action-neutral
* Add action-neutral CLI resolver selection
* Preserve API evidence across JSONL round trips
* Complete HarvestView API run parity
* Harden HarvestView run API contracts
* Remove obsolete bundled network snapshots
Delete the unused bundled AWS IP-range and resolver snapshots while preserving operator-supplied resolver file input.
* refactor: canonicalize URL results
* docs: define a bounded test budget
* Standardize hostname and IP result names
* fix(api): avoid duplicate evidence conflicts
2026-08-10 00:08:04 -04:00
Matt and GitHub
e4d37b05a8
Persist per-source run provenance ( #2516 )
...
* Persist per-source run provenance
* Keep the first JSONL contract unversioned
* Explain source yield counts
2026-08-09 11:50:08 -04:00
Matt and GitHub
6b02dbddc9
Share safe enumeration execution across transports ( #2507 )
...
* feat: share safe enumeration execution across transports
* fix: clarify safe scan contracts
* fix: preserve public screenshot redirects
* fix: restore operator-controlled active requests
* fix: allow operator-selected API scan targets
2026-08-07 16:02:16 -04:00
Matt and GitHub
7a854eda95
Contract DeHashed and LeakIX evidence ( #2506 )
...
* Contract DeHashed evidence handling
* Align LeakIX with its documented API
* Update provider capability selection
* Require REST auth for DeHashed results
2026-08-07 00:25:54 -04:00
Matt and GitHub
30ac342d9d
Remove unavailable Venacus source ( #2505 )
2026-08-07 00:04:47 -04:00
Matt and GitHub
ce791dcaca
Contract Leak-Lookup evidence handling ( #2504 )
...
* Contract Leak-Lookup evidence
* Preserve additional API compatibility
2026-08-07 00:01:26 -04:00
Matt and GitHub
eb7583227a
Expose authenticated recursive DNS through REST ( #2502 )
...
* Expose recursive DNS through REST
* Align REST recursive DNS limits and evidence
* Document hard recursive DNS query limits
* Reject non-finite recursive DNS REST runtimes
* Require operator authentication for REST recursion
2026-08-06 22:53:02 -04:00
Matt and GitHub
4f76b93513
Preserve direct DNS source result contracts ( #2494 )
...
* Harden explicit DNS direct source contracts
* Reject mismatched Shodan InternetDB evidence
* Preserve valid direct-source IP evidence
* Avoid ambiguous hostname output assertions
* Reference current Pentest-Tools scan documentation
2026-08-06 20:16:23 -04:00
Matt and GitHub
d60afe12e1
Retain GitLab evidence URLs ( #2492 )
2026-08-06 15:39:26 -04:00
Matt and GitHub
61d39dda3a
feat: add Arquivo.pt passive source ( #2490 )
2026-08-06 14:47:33 -04:00
Matt and GitHub
16c4866b49
fix: drive all from passive source catalog ( #2489 )
2026-08-06 14:47:33 -04:00