theHarvester
theHarvester theHarvester is the OSINT powerhouse for harvesting emails from search engines, PGP servers, and LinkedIn, resolving them to domains for targeted phishing or recon campaigns. Run its Python CLI with -d for domains and -b for sources, outputting CSV for follow-up validation. Open-source from laramies, it's the email excavator for pentesters digging public inboxes.
Explore →Recon-ng
Recon-ng Recon-ng's modules like recon/domains-contacts/pastebin_cache pull emails from pastes and social profiles, templating queries for scalable OSINT in domain footprints. Launch its Python console, load modules with set SOURCE, and run for aggregated intel. Open-source from lanmaster53, it's the modular miner for recon pros chaining email enum.
Explore →SpiderFoot
SpiderFoot SpiderFoot's sfp_email modules scrape emails from 100+ sources like DNS or social, correlating with targets for enriched OSINT graphs in automated hunts. Run its Python CLI with -s for seeds and -m for modules, outputting graphs or JSON. Open-source from smicallef, it's the web weaver for analysts spinning email threads from loose ends.
Explore →EmailHarvester
EmailHarvester EmailHarvester is the search-engine scraper for domain-specific emails via Google/Bing, limiting results to avoid bans while compiling lists for validation. Run its Python script with -d for domains and -t for engines, saving to files for deduping. Open-source from Da2x5, it's the engine extractor for recon rangers harvesting from SERPs.
Explore →SimplyEmail
SimplyEmail SimplyEmail takes seed emails to harvest associates from breaches, PGP keys, and social, resolving to domains for full contact mapping in OSINT workflows. Configure via Python with -i for inputs, running modules for enriched outputs. Open-source from securitygeneration, it's the contact connector for pentesters linking emails into networks.
Explore →Metagoofil
Metagoofil Metagoofil scrapes search engines for docs like PDFs with embedded emails, extracting metadata for user intel in document-based recon. Run its Python script with -d for domains and -t for types, limiting results for focused pulls. Open-source from epsylon3, it's the doc diver for auditors mining files for contact gold.
Explore →Email2Phonenumber
Email2Phonenumber Email2Phonenumber resolves emails to phone numbers via breach data and social OSINT, templating lookups for full profile enrichment in targeted hunts. Script its Python lib with seeds, outputting matched contacts for validation. Open-source from community, it's the number nexus for OSINT pros bridging inboxes to calls.
Explore →theHarvester-ng
theHarvester-ng theHarvester-ng is the forked evolution with enhanced email modules for PGP and Shodan queries, pulling contacts from diverse sources for broader recon coverage. Run via Python with -b for backends, customizing limits for noise reduction. Open-source fork from laramies, it's the harvest harvester for pentesters expanding email scopes.
Explore →Hunter.io API Wrapper
Hunter.io API Wrapper Hunter.io API Wrapper scripts email finding from domains via its Python client, verifying validity and pulling patterns for scalable contact harvesting. Auth with API keys, query via lib for JSON responses with confidence scores. Open-source wrapper from hunter-io, it's the email engineer for devs templating domain-to-address lookups.
Explore →email-osint

