TiloBox
Back to directory
Amass project preview

Amass

In-depth Attack Surface Mapping and asset discovery tool maintained by OWASP.

LicenseApache-2.0
GitHub stars11.5k
Last commit1 weeks ago
Tags5 topics
Owasp ToolAttack Surface MappingDns EnumerationOsint ReconnaissanceSecurity
Overview

Why consider Amass?

OWASP Amass is an open-source attack surface discovery and external asset mapping tool written in Go by the Open Worldwide Application Security Project (OWASP). Amass conducts network mapping using open-source intelligence (OSINT), active DNS enumeration, and graph database correlation.

Guided learning

Learn Amass by building

Practical setup notes, real use cases, and copy-ready examples in one focused guide.

1 min read 2 sections
In this guide2 sections

Overview of OWASP Amass

Amass uncovers unmapped subdomains and external cloud infrastructure across enterprise domains.

Quickstart

bash
1amass enum -d example.com

OWASP Amass is licensed under the Apache License Version 2.0.

Related tools

More options with a similar category or technology profile.

Amass FAQs

Amass is listed as a Developer Tools tool on TiloBox. Review the overview, features, and official documentation on this page to decide whether it solves your specific workflow.

Start with the project's GitHub repository and official website for supported installation and deployment instructions. Test the setup with representative data or a small project before rolling it out more widely.

Amass is listed under the Apache-2.0 license. Read the complete license text and the project's notices before using, modifying, or distributing the software.

Production readiness depends on your requirements. Review maintenance activity, security practices, documentation, backup and upgrade procedures, and compatibility with your stack; then validate it in a non-production environment.

Amass is listed as an alternative to Censys. Compare the core workflow, deployment model, integrations, and licensing against your must-have requirements before switching.