Files
theHarvester/docs/wiki/Quick-Start.md
T
MattandGitHub 1fd5749e52 Add an authenticated durable run API v1 (#2511)
* Model active evidence in result persistence

* Expose active action diagnostics

* Persist truthful DNS action evidence

* Persist direct action evidence

* feat: add authenticated durable run API v1

* Make API file interchange JSONL-only

* Harden API evidence boundaries

* Remove API rate limiter

* Unify API runs with result persistence

* Support target action runs

* Keep DNS resolver selection action-neutral

* Add action-neutral CLI resolver selection

* Preserve API evidence across JSONL round trips

* Complete HarvestView API run parity

* Harden HarvestView run API contracts

* Remove obsolete bundled network snapshots

Delete the unused bundled AWS IP-range and resolver snapshots while preserving operator-supplied resolver file input.

* refactor: canonicalize URL results

* docs: define a bounded test budget

* Standardize hostname and IP result names

* fix(api): avoid duplicate evidence conflicts
2026-08-10 00:08:04 -04:00

1.8 KiB

Quick start

These examples use the IANA-reserved example.com domain as inert test data. Replace it only with a target that is within your authorized scope.

Run a small passive query

From a source checkout:

uv run theHarvester -d example.com -b crtsh,certspotter

From Kali or another installed package, omit uv run:

theHarvester -d example.com -b crtsh,certspotter

This queries two passive certificate sources and prints consolidated findings. Passive does not mean private: the selected providers receive the target string.

Save a report

uv run theHarvester -d example.com -b crtsh,certspotter -f report

This writes report.json and report.xml in the current directory. JSON contains more result types and is the better automation format. See Results and Local Data.

Resolve discovered hosts

DNS resolution creates additional network activity. Use it only within scope:

AUTHORIZED_DOMAIN='replace-with-a-domain-you-control'
uv run theHarvester -d "$AUTHORIZED_DOMAIN" -b crtsh,certspotter -r

Pass a resolver IP, comma-separated resolver IPs, or a resolver file you create with one IP per line:

AUTHORIZED_DOMAIN='replace-with-a-domain-you-control'
uv run theHarvester -d "$AUTHORIZED_DOMAIN" -b crtsh -r resolvers.txt

Choose sources deliberately

The README source matrix shows the result types and credential requirements for every current source.

Do not start with -b all. It contacts many independent services and can consume quotas. It also increases runtime and makes provider failures harder to isolate.

Choose a small group of sources that provides the result types you need.

Use theHarvester -h for the current option and source list.