A penetration tester uses theHarvester to gather information about a target domain. Which of the following data types is theHarvester PRIMARILY designed to collect?
theHarvester queries public sources such as search engines, PGP key servers and certificate transparency logs, harvesting email addresses and subdomains tied to the target domain. That reconnaissance output feeds later phishing or enumeration phases, distinguishing it from port scanners and vulnerability tools.
Why this answer
theHarvester is an open-source intelligence (OSINT) tool designed to perform passive reconnaissance by querying public sources such as search engines (Google, Bing), PGP key servers, and the Shodan API. Its primary function is to collect email addresses, subdomains, IP addresses, and virtual hosts associated with a target domain, aiding in the footprinting phase of a penetration test.
Exam trap
The trap here is that candidates confuse theHarvester's passive OSINT collection with active scanning or exploitation tools, leading them to select options related to network traffic, password cracking, or vulnerability scanning.
How to eliminate wrong answers
Option A is wrong because theHarvester does not capture live network traffic; that is the function of packet sniffers like tcpdump or Wireshark, which operate at the data-link layer. Option B is wrong because theHarvester does not extract password hashes; hash retrieval is typically performed by tools like Hashcat or John the Ripper after obtaining a password database dump. Option D is wrong because theHarvester does not perform vulnerability scanning; vulnerability assessment is done by tools like Nessus or OpenVAS, which actively probe services for known CVEs.