Performs in-depth attack surface mapping and external asset discovery using open source intelligence and active reconnaissance.
OWASP Amass is an open-source security tool that performs in-depth attack surface mapping and external asset discovery. It uses open source information gathering and active reconnaissance techniques to identify internet-facing infrastructure, helping organizations understand their exposure to potential threats.
Security professionals, penetration testers, red teams, and organizations looking to map their external attack surface and identify potential vulnerabilities.
Developers choose Amass for its comprehensive approach to reconnaissance, combining multiple data sources and active techniques into a single tool, and its status as an OWASP flagship project ensures community trust and ongoing development.
In-depth attack surface mapping and asset discovery
Open-Awesome is built by the community, for the community. Submit a project, suggest an awesome list, or help improve the catalog on GitHub.
Aggregates data from numerous public sources like SSL certificates and DNS records, as highlighted in its Open Source Intelligence Gathering feature.
Performs DNS enumeration and brute-forcing to discover subdomains and assets, enabling thorough attack surface mapping.
As an OWASP flagship project, it benefits from community support, ongoing development, and corporate backing, evidenced by badges and documentation.
Offers multiple installation methods including Go binaries and Docker images, making it accessible across different environments.
Requires managing API keys for various data sources and understanding command-line options, which can be daunting without extensive documentation.
Focuses solely on asset discovery and mapping; it does not scan for vulnerabilities, necessitating additional tools for complete security workflows.
Active reconnaissance techniques like brute-forcing can generate detectable traffic, which might alert targets or violate ethical guidelines if not used carefully.