
Amass
OWASP Amass maps external attack surface by discovering domains, addresses and related assets through open-source intelligence and active techniques.
0 upvotes · 0 downvotes
- Pricing
- Free
- Platforms
- LinuxWindowsmacOS
- Licence
- Open source
- Reviewed
- Last reviewed 1 October 2026
- Links
- GitHub
What it is
OWASP Amass is an open-source attack-surface mapping and asset discovery toolkit maintained under the OWASP Amass project. Practitioners use it to enumerate domains, IP addresses and related infrastructure with a mix of open-source intelligence (OSINT) collectors and optional active techniques. It is a long-standing favourite for reconnaissance before authorised web and external assessments.
What it helps with
- Discovering subdomains and related DNS names across large scopes.
- Combining many data sources for passive reconnaissance workflows.
- Running active enumeration options when engagement rules allow.
- Tracking assets over time and exporting results for further tooling.
- Visualising or graphing relationships between discovered assets where supported.
- Fitting into OSINT and external attack-surface programmes alongside other recon tools.
Who it's for
Penetration testers, bug bounty hunters and OSINT practitioners who need structured external asset discovery on domains they are authorised to assess.
Worth knowing
Use Amass only against organisations and domains within a clear written scope. Active techniques can generate noticeable network traffic. Amass is free and open source under licences documented in the owasp-amass/amass repository. Official project materials live on GitHub under OWASP Amass. Attribution: framing from the OWASP Amass README and project documentation.