theHarvester: OSINT Tool for Emails and Subdomains
A penetration tester uses theHarvester to gather information about a target domain. Which of the following data types is theHarvester PRIMARILY designed to collect?
Quick Answer
The correct answer is email addresses and subdomains, as theHarvester is primarily designed to collect these two data types during passive reconnaissance. This open-source intelligence (OSINT) tool queries public sources like Google, Bing, PGP key servers, and the Shodan API to gather email addresses, subdomains, IP addresses, and virtual hosts associated with a target domain, all without directly interacting with the target’s infrastructure. On the Certified Ethical Hacker CEH exam, this question tests your understanding of the footprinting phase and the distinction between passive and active reconnaissance—a common trap is confusing theHarvester’s primary purpose with tools like Nmap or Maltego, which focus on network scanning or relationship mapping. Remember that theHarvester’s name hints at its function: just as a harvester gathers crops, this tool harvests emails and subdomains from public fields. A quick memory tip: think “E & S” for Emails and Subdomains, the two core outputs that make theHarvester a go-to for initial domain profiling.
⚠ Common exam trap
Many exam-takers confuse theHarvester's passive OSINT collection with active scanning or exploitation tools, leading them to select options related to network traffic, password cracking, or vulnerability scanning.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Email addresses and subdomains
theHarvester is an open-source intelligence (OSINT) tool designed to perform passive reconnaissance by querying public sources such as search engines (Google, Bing), PGP key servers, and the Shodan API. Its primary function is to collect email addresses, subdomains, IP addresses, and virtual hosts associated with a target domain, aiding in the footprinting phase of a penetration test.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Live network traffic captures
Why it's wrong here
theHarvester queries search engines, PGP key servers and Shodan for emails, subdomains, hosts and employee names; it never captures packets. Packet capture belongs to Wireshark, tcpdump or a span/mirror port during active reconnaissance, which is why live traffic captures are tempting here.
- ✗
Passwords hashes
Why it's wrong here
theHarvester performs open-source intelligence collection, returning emails, subdomains and hostnames; it does not extract credential material. Hash extraction requires dumping SAM, NTDS.dit or /etc/shadow with tools such as Mimikatz or secretsdump after obtaining privileged access, which is why password hashes appear plausible.
- ✓
Email addresses and subdomains
Why this is correct
theHarvester queries public sources such as search engines, PGP key servers and certificate transparency logs, harvesting email addresses and subdomains tied to the target domain. That reconnaissance output feeds later phishing or enumeration phases, distinguishing it from port scanners and vulnerability tools.
- ✗
Vulnerability scan results
Why it's wrong here
theHarvester aggregates open-source intelligence such as emails, subdomains, hosts and employee names from public sources; it performs no vulnerability scanning, which requires tools like Nessus or OpenVAS. It is tempting because reconnaissance and scanning both precede exploitation, but they are distinct phases collecting different data.
Go deeper
Related to this question
About these practice questions
One of 913 original CEH practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
Same concept, more angles
3 more ways this is tested on CEH
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. Which TWO OSINT tools are commonly used to gather email addresses and subdomains associated with a target domain? (Select 2)
medium- A.Nmap
- B.Nessus
- ✓ C.theHarvester
- ✓ D.Maltego
- E.Shodan
Why C: theHarvester (C) is correct because it is a dedicated OSINT reconnaissance tool that queries public sources such as search engines, PGP key servers, and certificate transparency logs to harvest email addresses, employee names, hosts, and subdomains for a target domain. Maltego (D) is also correct because it is a graphical link-analysis and OSINT platform whose transforms aggregate data from DNS records, WHOIS, certificate transparency, and other public sources to map domains, subdomains, and associated email addresses. Nmap (A) is a port scanner and host-discovery tool, not an email/subdomain OSINT collector, so it does not fit. Nessus (B) is a vulnerability scanner that assesses hosts for weaknesses rather than enumerating emails and subdomains. Shodan (E) is an internet-connected-device search engine that indexes exposed services and banners, not a tool primarily used to harvest email addresses and subdomains for a domain.
Variation 2. During a penetration test, a tester wants to gather email addresses, subdomains, and employee names associated with a target domain. Which of the following tools is specifically designed for such passive reconnaissance?
easy- A.Wireshark
- ✓ B.theHarvester
- C.Metasploit
- D.Nmap
Why B: theHarvester is a passive reconnaissance tool specifically designed to gather email addresses, subdomains, employee names, and other open-source intelligence (OSINT) from public sources such as search engines (Google, Bing), PGP key servers, and the Shodan database. It operates without sending direct packets to the target, making it ideal for passive footprinting as defined in the CEH methodology.
Variation 3. A penetration tester is performing reconnaissance and wants to identify email addresses associated with a target domain. Which tool is specifically designed for this purpose?
medium- A.Nmap
- ✓ B.theHarvester
- C.Shodan
- D.Maltego
Why B: TheHarvester is specifically designed for passive reconnaissance to gather email addresses, subdomains, and other open-source intelligence (OSINT) from public sources like search engines, PGP key servers, and the SHODAN database. It directly queries these sources to extract email addresses associated with a target domain, making it the correct tool for this task.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CEH practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CEH exam.