Automic VaultAutomic Vault

brew

theharvester を Homebrew, Nix でインストール

theharvester のインストール経路、実行ファイル、メタデータ、AI エージェント向けセキュリティノートを確認します。

インストール

追加のインストールコマンド

macOS

Homebrew確認済み · 100%
brew install theharvester

local Homebrew formula metadata

Linux

Nix確認済み · 92%
nix profile install nixpkgs#theharvester

nixpkgs package indexes · pkgs/by-name/th/theharvester/package.nix · ソース: api.github.com

概要

パッケージ概要

Gather materials from public sources (for pen testers)

コマンドとエイリアス

  • restfulHarvest
  • theHarvester
  • theharvester

履歴

プロジェクトの歴史と使われ方

theHarvester is an OSINT and reconnaissance tool for gathering emails, names, subdomains, IPs, and URLs from public data sources during the early stages of a penetration test. The official wiki describes it as simple but effective for mapping an organization's external threat landscape.

プロジェクトの歴史

The project is maintained in the laramies/theHarvester repository and is described by its README as an emails, subdomains, and names harvester for OSINT. Over time it has become a Python security tool with a long module list: the README enumerates passive data sources such as search engines, certificate transparency services, threat-intelligence APIs, code search, and internet-exposure databases.

採用の歴史

The official installation wiki explicitly says the easiest way to use theHarvester is through Kali Linux, where users can run `theHarvester -h`. The same page also documents pipx, Docker, and source-based installation, while the repository page shows a large GitHub audience and dozens of official releases. In package-manager culture, its presence in Homebrew and Nix gives macOS and reproducible-environment users a route to a tool historically associated with security distributions.

使われ方

Typical use is passive reconnaissance: users configure API keys when needed, select modules or data sources, and collect public-facing identifiers for a target domain. The README's passive module list shows why API-key management matters: many useful sources have quotas, pricing, or authenticated access, and the wiki documents where `api-keys.yaml` lives under packaged and cloned installs.

パッケージ好きにとっての重要性

theHarvester matters to package nerds because it is a classic security CLI that crosses the boundary between specialist pentest distros and general-purpose package managers. A Homebrew formula turns a Kali-associated recon workflow into a one-command install on macOS, while the tool's module list creates a constant packaging concern around Python dependencies, browser automation, and optional API credentials.

タイムライン

  • 2020: Official GitHub wiki home page revision describes the tool's early-pentest OSINT role.
  • 2025-2026: Official GitHub tags page shows active 4.x releases.
  • 2026: Installation wiki documents Kali, pipx, Docker, and source workflows.
  • 2026: Repository page shows release 4.11.1 as the latest release on June 3, 2026.

Related projects

  • Related tools include other OSINT and recon CLIs such as subdomain enumerators, certificate-transparency query tools, internet search APIs, Shodan-like asset search tools, and Kali Linux reconnaissance utilities. theHarvester's niche is aggregating many public sources behind one command-line interface.

ソース

セキュリティ状態

保護ツール対応はまだ見つかっていません

theharvester に一致するローカルシークレット処理マニフェストは見つかりませんでした。将来の対応で安定したパッケージ URL を使えるよう、Nucleus パッケージメタデータはここに公開されています。

インストール挙動

  • formula メタデータに Homebrew post-install フックは記録されていません。
  • Homebrew bottle メタデータは 6 個のプラットフォームターゲットで利用できます。
  • 5 件の実行時依存関係とともにインストールされます。
  • ビルドメタデータには 1 件のビルド依存関係があります。

推奨レビュー

エージェントに無人実行させる前に、このツールが平文の認証情報を読むか、リモート状態を書き込むか、成果物を公開するか、プラグインを起動するかを確認してください。

local files

Configuration and credential file locations

These source-backed paths show where this package keeps local settings or durable credentials. Automic Vault can use them as review targets for secret scanning, migration, and command approval.

Credential files

Credential-bearing paths to review before unattended agent runs.

Linux
/etc/theHarvester/api-keys.ymlapi-keys.yaml
macOS
/usr/local/etc/theharvester/api-keys.yamlapi-keys.yaml

実行可能ファイル

インストールされる実行可能ファイル

コマンド種類公開範囲メモ
restfulHarvestcliグローバル実行可能ファイル
theHarvestercliグローバル実行可能ファイル
theharvestercliグローバル実行可能ファイル

鮮度

バージョンと鮮度

これらの信号は、ページ生成時期、パッケージマネージャの活動、上流リリース比較を分けて示します。バージョン遅れは、証拠 URL と比較可能なバージョンがある場合だけ警告されます。

ページ生成日2026-07-25
マネージャ版4.11.1
マネージャ更新日2026-06-16
ローカルデータOK
上流最新
検出された最新4.11.1

https://github.com/laramies/theHarvester

  • OK鮮度警告は生成されていません。

インストールメタデータ

パッケージメタデータ

パッケージキーbrew:theharvester
バージョン4.11.1
パッケージマネージャHomebrew
パッケージマネージャページhttps://formulae.brew.sh/formula/theharvester
ホームページhttps://www.edge-security.com
リポジトリhttps://github.com/laramies/theHarvester
上流ドキュメントhttps://github.com/laramies/theHarvester#readme
ライセンスGPL-2.0-only
ソースアーカイブhttps://github.com/laramies/theHarvester/archive/refs/tags/4.11.1.tar.gz
最終更新2026-06-16T13:15:41Z
Pulseupdated
依存関係certifi, cffi, libyaml, pydantic, python@3.14
ビルド依存関係cmake
macOS 提供ライブラリlibffi, libxml2, libxslt
Bottle利用可能 (対象 arm64_linux, arm64_sequoia, arm64_sonoma, arm64_tahoe, sonoma, x86_64_linux)
Homebrew post-install未定義
サービス宣言なし

レジストリ情報

ソースデータベース詳細

Source DatabaseHomebrew formula API
Taphomebrew/core
Full Nametheharvester
Version Scheme0
Revision1
Head VersionHEAD
Bottle Stable Root URLhttps://ghcr.io/v2/homebrew/core
Deprecatedno
Disabledno
Keg Onlyno
URL Keys
  • head
  • stable

ソースデータベース一致

他のパッケージマネージャ記録

一致は外部パッケージマネージャインデックスから取得され、ローカルの Automic Vault パッケージリンクとは分けて表示されます。

Nix95%

theharvester

nix profile install nixpkgs#theharvester
  • normalized package name match
  • 一致条件: Theharvester
nixpkgs package indexes · api.github.com · nixpkgs package indexes: pkgs/by-name/th/theharvester/package.nix from https://api.github.com/repos/NixOS/nixpkgs/git/trees/master?recursive=1

ソース経路

リポジトリデータから生成

このページは scripts/generate-pkg-sqlite.py が生成した非公開のパッケージ SQLite アーティファクトから av-web によって提供されます。

使用ソース

  • Geiger risk classifier
  • Nucleus package database
  • av.db category and tag curation
  • cross-ecosystem install command graph
  • curated configuration and credential file locations
  • curated package history
  • external package-manager database matches
  • package relationship graph
  • package version freshness
  • package-page enrichment