Skip to content

Milestones

List view

  • ## Goal Measurably increase theHarvester's yield of currently addressable, in-scope subdomains while preserving the evidence behind each result and making source failures, scope decisions, and active behavior visible. This milestone follows the reliability and discovery-improvements batch. It keeps the core a finite, one-shot enumerator; it is not a rewrite or a commitment to continuous monitoring. ## Workstreams - Establish deterministic, consented benchmark fixtures and quality gates for valid yield, wildcard false positives, IPv6 coverage, scope, runtime, and provider cost. - Create one executable source catalog for canonical names, aliases, credentials, capabilities, activity class, lifecycle, pagination, and declared limits. - Preserve per-source discovery observations, source-execution outcomes, collection time, derivation, and source family through deduplication. - Add versioned lossless JSONL output while preserving existing CLI, JSON, XML, REST, and SQLite compatibility. - Correct DNS validation for A, AAAA, and CNAME chains, including resolver disagreement and depth-aware wildcard controls. - Complete bounded pagination and current-index traversal for existing certificate, archive, code-search, and passive-DNS sources. - Benchmark learned candidate generation and bounded recursive DNS discovery behind explicit DNS authorization and query/runtime budgets. - Add or retain providers only when repeatable benchmarks show incremental currently addressable yield or a clear correctness improvement. - Keep terminal output understandable by separating currently addressable results, secondary evidence, needs-review results, and scope-extension candidates. ## Completion criteria - A benchmarked configuration increases unique currently addressable subdomain yield over the frozen baseline. - No out-of-scope entity is promoted or used for recursive discovery without explicit authorization. - No P1 DNS or P2 direct activity runs unless selected by the operator. - Every selected source reports a deterministic outcome such as succeeded, empty, failed, rate-limited, or skipped. - Deterministic fixtures have complete accounting with no known false result classified as currently addressable. - Pagination, wildcard handling, DNS validation, provider failures, and partial results have offline regression coverage. - Existing operator-facing interfaces remain compatible during the additive migration.

    No due date
    9/9 issues closed