theharvester_search
Run OSINT reconnaissance on a domain to collect emails, subdomains, hosts, IPs, and URLs from public sources.
Instructions
Run theHarvester to gather OSINT on a domain. Collects emails, subdomains, hosts, IPs, and URLs from various public sources.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| limit | No | Maximum number of results to return (default: 500) | |
| domain | Yes | Target domain to search (e.g., 'example.com') | |
| shodan | No | Query Shodan for discovered hosts | |
| sources | No | Data sources to use. Available: anubis, baidu, bevigil, binaryedge, bing, bingapi, brave, bufferoverun, censys, certspotter, criminalip, crtsh, dnsdumpster, duckduckgo, fullhunt, github-code, hackertarget, hunter, hunterhow, intelx, leakix, netlas, onyphe, otx, pentesttools, projectdiscovery, rapiddns, rocketreach, securityscorecard, securitytrails, shodan, sitedossier, subdomaincenter, subdomainfinderc99, threatminer, tomba, urlscan, virustotal, yahoo, zoomeye. Leave empty for 'all'. | |
| takeover | No | Check for subdomain takeover vulnerabilities | |
| dns_brute | No | Perform DNS brute force enumeration | |
| dns_resolve | No | Perform DNS resolution on discovered subdomains |