All integrations
theHarvester logo
// Tentacle Tool · OSINT

Cracken + theHarvester

Cracken runs theHarvester to pull a domain's employee names, emails, subdomains, and hosts out of public sources. It starts the operation from that list.

Get started
// 01

Connecting theHarvester

Connect with

No credentials — runs on your own Tentacle

Cadence

Runs on demand — installed per Tentacle, then invoked during an operation

Requires

Linux or macOS Tentacle

// 02

What Cracken gets from theHarvester

  • For a domain, harvested email addresses

  • Employee/people names

  • Subdomains and hostnames

  • IP addresses and ASNs — all gathered from public sources

// 03

What theHarvester does not do

Passive OSINT from public sources only — it does not actively scan or contact the target. Cracken does not version-check the installed binary.

// 04

How Cracken uses theHarvester

  1. 01

    Install theHarvester on a Tentacle

  2. 02

    Name the domain in scope

  3. 03

    Harvest, then work the list

  4. 04

    Confirm the Tentacle is ready

// 05

Frequently asked questions

Does theHarvester touch my servers when Cracken runs it?

No — theHarvester is passive: it queries search engines, certificate transparency logs, and third-party databases about a domain, never connecting to that domain's systems.

Do I have to supply API keys to use theHarvester?

No — most of theHarvester's sources work without credentials; keys for sources like Shodan, Censys, or SecurityTrails widen results and stay on the Tentacle.

“I've been pretty impressed with how CrackenAGI is able to do its vulnerability discovery, enumeration, reconnaissance, as well as eventually being able to actually execute different exploitation paths.”

Cybersecurity Engineer, red team · test-and-measurement manufacturer

Attack with real theHarvester context.

See how Cracken runs theHarvester on a Tentacle you host, and proves what it finds end to end.