theHarvester
theHarvester -d <domain> -b all
Collects emails, subdomains, hosts, and URLs from OSINT sources like Google, Bing, LinkedIn, Shodan, and more.
Initial passive reconnaissance phase, before touching the client's network. Use it to map the target domain's exposed surface: employees, external services, and subdomains. In banking or public sector, corporate emails often appear in forums or public repositories, giving you leads for phishing attacks or VPN user enumeration.
When the client has strict privacy policies and search engines return captchas. Also avoid the '-b all' mode if you don't want to saturate your IP with requests to hundreds of sources; egress firewalls may flag you as a scanner. If the engagement is internal and you already have access, this tool adds no value: prioritize BloodHound or ldapsearch.