OWASP Amass
In-depth subdomain enumeration and attack surface mapping using passive and active techniques.
External Tool
This open-source tool is maintained externally. View the source on GitHub to learn more or run it yourself.
Browse network tools →What's next with OWASP Amass?
Choose how you want to get started.
Use it free
Open the official tool or demo — no account needed.
Self-host it
Run the open-source version on your own infrastructure.
What is OWASP Amass?
OWASP Amass is an open-source tool designed for network mapping and external asset discovery, enabling security professionals to identify potential attack surfaces and vulnerabilities in an organization's digital infrastructure. By leveraging open-source intelligence (OSINT) and active reconnaissance techniques, it helps users systematically uncover exposed assets, subdomains, and services that may be exploitable. This tool is primarily used by cybersecurity teams, red-hat teams, and penetration testers to conduct comprehensive security assessments and improve defensive strategies. It addresses the challenge of identifying hidden or overlooked assets that could be exploited by adversaries, providing a structured approach to mapping an organization's digital footprint. The tool operates by aggregating data from public sources, such as DNS records, WHOIS databases, and certificate authorities, while also performing active probing to discover additional assets. Its modular design allows integration with other security tools, enhancing its utility in both offensive and defensive operations. OWASP Amass is particularly valuable in environments where rapid identification of exposed resources is critical, such as during incident response or pre-engagement reconnaissance. Its ability to scale and adapt to different network environments makes it a cornerstone in modern cybersecurity workflows.
How it works
OWASP Amass is an open-source tool developed by the OWASP Foundation to map attack surfaces and discover external assets through passive and active reconnaissance. It is designed to assist security professionals in identifying potential vulnerabilities by systematically analyzing public and private data sources. The primary purpose of Amass is to provide a structured method for uncovering exposed services, subdomains, and network components that may be susceptible to exploitation. It is widely used in penetration testing, threat intelligence gathering, and security audits to strengthen an organization's defensive posture. Amass excels in passive data collection, such as gathering DNS records, WHOIS information, and certificate data from public sources. It also supports active reconnaissance techniques like subdomain enumeration and service discovery, enabling users to uncover assets not visible through passive methods.
How to use it
- 1Install Amass using Go (requires a Go environment) or download precompiled binaries from the GitHub repository. 2. Run the tool with a target domain, e.g., `amass enum -d example.com` to initiate subdomain discovery. 3. Use command-line flags to specify data sources, output formats, and active probing parameters. 4. Analyze the results, which include lists of discovered assets, DNS records, and potential vulnerabilities. Practical tips: Combine Amass with tools like Nmap or Nikto for deeper analysis. Use the `-passive` flag to prioritize passive data collection, and the `-active` flag for targeted active scanning. Regularly update the tool to leverage the latest data sources and features.
What it can do
- attack surface enumeration
Use cases
Assumptions and limitations
Assumptions
- source: https://github.com/owasp-amass/amass
- license: Apache-2.0 — free to use
- privacy: Self-hosted — you control your data
Limitations
- Reliance on public data sources may miss internal or private assets.
- Active reconnaissance could trigger security defenses or rate limiting.
- Requires advanced technical knowledge to configure and interpret results.
- Resource-intensive operations may impact network performance if not managed carefully.
- Lacks a graphical user interface (GUI), limiting accessibility for non-technical users.
Understanding the result
In-depth subdomain enumeration and attack surface mapping using passive and active techniques.
Tool details
- Clearly flagged when a network request is needed.
- No account, no sign-up, and no tracking of your content.
- Powered by (Apache-2.0).
- Built with
- (owasp-amass/amass)
- License
- Apache-2.0
- Runs locally
- No — requires a network request
- Verification
- Not yet verified
- Input
- Query
- Output
- Text
Built with owasp-amass/amass. OpenToolVault provides the discovery and browser interface while crediting the original project maintainers.
- Built with
- License
- Apache-2.0
Open-source project
OpenToolVault is an independent directory. We are not affiliated with or endorsed by this project.
References
- / — GitHub Repository
Upstream project · GitHub
- Apache-2.0 License
Upstream project
Frequently asked
What is OWASP Amass used for?
OWASP Amass is used for attack surface mapping and external asset discovery, helping security teams identify exposed resources, subdomains, and services that may be vulnerable to exploitation. It is commonly employed in penetration testing, security audits, and threat intelligence gathering to strengthen an organization's defensive strategies.
How does OWASP Amass perform reconnaissance?
Amass combines passive and active reconnaissance techniques. Passive methods include collecting data from public sources like DNS records, WHOIS databases, and certificate authorities. Active methods involve subdomain enumeration, service discovery, and network probing to uncover assets not accessible through passive means. It also integrates with external APIs for real-time data updates.
How do I perform a subdomain scan with Amass?
To perform a subdomain scan, run the command `amass enum -d target.com` in the terminal. This initiates passive data collection from public sources. For active scanning, use `amass enum -d target.com -active` to include targeted probing. Customize parameters like `-passive` or `-active` to adjust the scan's intensity and scope.
How does Amass compare to tools like sublist3r or AssetMapper?
Amass offers broader integration with external data sources and supports both passive and active reconnaissance, whereas sublist3r focuses primarily on subdomain enumeration. AssetMapper emphasizes internal network mapping. Amass's modular design allows for greater customization, but it requires more technical expertise compared to user-friendly alternatives.
How do I troubleshoot connection errors in Amass?
Connection errors may occur due to network restrictions or blocked ports. Verify that the target domain is reachable and that firewalls or proxies are configured correctly. Use the `-proxy` flag to specify a proxy server if required. For DNS-related issues, ensure the `dnsserver` configuration in the `config.json` file is set to a valid DNS resolver.