
Cracken + theHarvester
Cracken runs theHarvester to pull a domain's employee names, emails, subdomains, and hosts out of public sources. It starts the operation from that list.
Connecting theHarvester
- Connect with
No credentials — runs on your own Tentacle
- Cadence
Runs on demand — installed per Tentacle, then invoked during an operation
- Requires
Linux or macOS Tentacle
What Cracken gets from theHarvester
For a domain, harvested email addresses
Employee/people names
Subdomains and hostnames
IP addresses and ASNs — all gathered from public sources
What theHarvester does not do
Passive OSINT from public sources only — it does not actively scan or contact the target. Cracken does not version-check the installed binary.
How Cracken uses theHarvester
- 01
Install theHarvester on a Tentacle
- 02
Name the domain in scope
- 03
Harvest, then work the list
- 04
Confirm the Tentacle is ready
Frequently asked questions
Does theHarvester touch my servers when Cracken runs it?
No — theHarvester is passive: it queries search engines, certificate transparency logs, and third-party databases about a domain, never connecting to that domain's systems.
Do I have to supply API keys to use theHarvester?
No — most of theHarvester's sources work without credentials; keys for sources like Shodan, Censys, or SecurityTrails widen results and stay on the Tentacle.
“I've been pretty impressed with how CrackenAGI is able to do its vulnerability discovery, enumeration, reconnaissance, as well as eventually being able to actually execute different exploitation paths.”
Attack with real theHarvester context.
See how Cracken runs theHarvester on a Tentacle you host, and proves what it finds end to end.




