CompTIA PenTest+ (PT0-003)Reconnaissance and EnumerationEasy

A penetration tester is performing OSINT against a client organization. They want to find email addresses associated with the target domain. Which tool is specifically designed to harvest email addresses, employee names, and subdomains from public sources like search engines, PGP key servers, and SHODAN?

  1. AtheHarvester
  2. BRecon-ng
  3. CSpiderFoot
  4. DMaltego
Show answer & explanation

Correct answer: A. theHarvester

theHarvester is a dedicated OSINT tool specifically designed to gather email addresses, subdomains, hostnames, employee names, and open ports from various public sources, including search engines and PGP key servers.

Why the other options are wrong

  • B. Recon-ng is a full OSINT framework, but theHarvester is a more direct tool for the specific task of harvesting emails.
  • C. SpiderFoot is an automated OSINT framework, but theHarvester is a more focused utility for the task described.
  • D. Maltego is a link analysis tool that visualizes relationships, but theHarvester is more specialized for initial data collection.

theHarvester

An OSINT tool used to gather public information (emails, subdomains, hostnames, employee names, banners, open ports) from various public sources for a given target domain or company name.

  • Automates collection of email addresses and subdomains.
  • Leverages search engines (Google, Bing, Baidu), PGP key servers, LinkedIn, etc.
  • Useful for initial reconnaissance to build a target profile.
  • Command-line tool, easy to use.

Memory trick: Harvesters collect public data.

More Reconnaissance and Enumeration questions