Amass Favicon

Amass

OWASP open-source subdomain enumeration and network mapping tool using passive and active techniques to discover attack surfaces.

OSINT Subdomain Enumeration Network Mapping Asset Discovery

Overview

Amass is a comprehensive open-source subdomain enumeration and network mapping tool developed by OWASP. It uses a combination of passive data collection from public sources and active DNS techniques to discover an organization's attack surface. Key features include DNS resolution, zone transfers, certificate transparency logs, search engine scraping, and integration with third-party APIs. Amass provides multiple output formats and visualization capabilities, making it essential for security teams performing asset discovery and attack surface management.

Primary Use Cases

Discovering subdomains and organizational assets through passive and active reconnaissance.
Mapping network infrastructure through DNS analysis and certificate transparency logs.
Conducting attack surface management to identify potential vulnerabilities and unauthorized services.

Frequently Asked Questions

Amass is an open-source subdomain enumeration tool developed by OWASP. It discovers an organization's attack surfaces using passive and active techniques.

Yes, Amass is completely free and open-source under the Apache 2.0 license. It is maintained by the OWASP community and actively updated.

Amass uses a combination of passive data collection (search engines, certificate logs, DNS databases) and active techniques (DNS brute-force, zone transfers) to discover subdomains.

Yes, Amass integrates with tools like Maltego, provides API support, and offers multiple output formats (JSON, XML, CSV) for easy integration with other security workflows.

Amass is designed for scalability with support for multiple data sources, concurrent DNS resolutions, and the ability to handle large domain portfolios and extensive reconnaissance projects.

Metadata

Official Website Visit Website
Category Info

Open Source Intelligence (OSINT) tools for gathering and analyzing publicly available information from various sources including websites, social media, DNS records, public databases, and other open data sources for security investigations and threat intelligence.

Added On

August 18, 2026

Last Updated

August 18, 2026

OSINT

Command-line OSINT tool for gathering emails, subdomains, and employee names from public sources including search engines, PGP key servers, ...

OSINT

Popular service for checking if email addresses or passwords have been exposed in data breaches, providing essential security intelligence.

OSINT

Industry-leading threat intelligence platform that analyzes files, URLs, and IP addresses using 70+ antivirus engines and threat detection s...