OWASP Amass

Maps an organisation's external attack surface, finding subdomains through passive sources, DNS enumeration and certificate data.

Open OWASP Amass ↗

https://github.com/owasp-amass/amass

Type
Command line
Cost
Free
Touches the target?
Yes, can be active
Account needed
No
Category
Domains & DNS
Language
Go
License
Apache-2.0
Platforms
linux, macos, windows
GitHub stars
15,225
Last updated
2026-07-19
Link status
Online, checked 2026-09-26

Takes

Gives you

  • Domain
  • IP address

Install

brew install amass

Source: github.com/owasp-amass/amass · Docker image available

Where to go next

Found something with OWASP Amass? These tools take it as input.

Similar tools

Community database of fake banks, shipping companies and other scam websites, with reports and screenshots.

  • Website
  • Freemium

TakesDomain

Community database of reported malicious IPs. Shows abuse reports, a confidence score, the ISP and the usage type.

  • Website
  • Freemium

TakesIP addressDomain

Community threat-intelligence exchange. Look up an IP, domain or file hash to see the reports and campaigns it appears in.

  • Website
  • Free
  • Account

TakesIP addressDomainFile hash

Generates variations of known subdomains (dev-, -staging, numbers) and resolves them to find hidden hosts.

  • Command line
  • Free
  • Active

TakesDomain

Annual reports from thousands of listed companies worldwide, including past years, in one searchable place.

  • Website
  • Free

TakesCompany

Official registry lookup for IP ranges and networks in North America: who holds an address block and their contacts.

  • Website
  • Free

TakesIP addressCompany