2 Results and Local Data
NotoriousRebel edited this page 2026-07-29 11:59:58 -04:00

Results and local data

theHarvester can print findings, write reports, retain selected records in SQLite, save screenshots, and return REST JSON. These outputs have different schemas and sensitivity.

Terminal output

The CLI groups findings by result type. It can also print separate enrichment, such as Shodan output. Use terminal output for operators, not as a stable automation interface.

JSON and XML reports

Use -f NAME to write both formats:

uv run theHarvester -d example.com -b crtsh,certspotter -f report

This creates report.json and report.xml.

  • JSON is one object and contains the broader result set. cmd, hosts, and shodan are always present; other fields appear when non-empty.
  • XML contains the command, emails, hosts, and virtual hosts. Use JSON for other result types.
  • Current JSON and XML reports do not record which source found each item.

Host values may be plain hostnames. When DNS resolution is enabled, they can also use the hostname:IP form.

The repository README output section documents the current fields and provides copyable jq examples.

SQLite database

Host, email, IP, and related records are stored at:

~/.local/share/theHarvester/stash.sqlite

The database persists across runs. Account for it in engagement cleanup and retention procedures.

Screenshots

--screenshot DIR writes browser captures to the selected directory. Screenshots may contain authentication pages, internal names, or other sensitive visual data even when no credentials were used.

REST JSON

The REST /query response returns arrays for ASNs, interesting URLs, Twitter/LinkedIn data, Trello URLs, IPs, emails, and hosts. Treat runtime /docs, /redoc, and OpenAPI as the exact request/response reference.

Handling and sharing

  • Store results only where the engagement permits.
  • Remove reports, screenshots, and the SQLite database when retention expires.
  • Do not commit collected output to theHarvester or attach raw target data to public issues.
  • Share only the minimum sanitized output needed to reproduce a problem.
  • Remove credentials, private targets, account details, and unnecessary provider response content.