← All cheat sheets

AMASS

Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.

Interactive tool: Recon / OSINT Helper

OVERVIEW#

OWASP Amass performs in-depth attack surface mapping and asset
discovery: subdomain enumeration, DNS, ASN/netblock, and graph-based
correlation from passive + active sources. Modern replacement/complement
to older DNS enum tools. Authorized scope only.

SUBCOMMANDS#

amass enum      # Discover subdomains / assets
amass intel     # Collect intelligence (ASNs, orgs, whois, TLS)
amass db        # Query the local results graph database
amass viz       # Export graph visualizations
amass track     # Compare enumerations over time (diff)

PASSIVE ENUM (STEALTHY)#

amass enum -passive -d corp.lu               # Passive only, no DNS resolve
amass enum -passive -d corp.lu -o subs.txt   # Save results
amass enum -passive -df domains.txt          # Multiple domains from file
# Passive uses OSINT sources only - no direct traffic to target infra

ACTIVE ENUM#

amass enum -active -d corp.lu                # Include zone transfers, certs
amass enum -active -d corp.lu -brute         # Add brute force
amass enum -brute -w wordlist.txt -d corp.lu # Custom brute wordlist
amass enum -active -d corp.lu -ip            # Show resolved IPs
amass enum -d corp.lu -src                   # Show which source found each

INTEL / ASN / ORG#

amass intel -d corp.lu                        # Root domain intel
amass intel -org "Corp Bank"                  # Find ASNs by org name
amass intel -asn 12345                         # Enumerate an ASN
amass intel -cidr 192.0.2.0/24                # Reverse from a netblock
amass intel -whois -d corp.lu                 # Reverse whois expansion

SOURCES / API KEYS#

amass enum -list                              # List data sources
# Config file adds API keys (Shodan, Censys, VirusTotal, SecurityTrails,
# etc.) for much broader passive coverage:
amass enum -passive -d corp.lu -config config.yaml

DATABASE & OUTPUT#

amass db -names -d corp.lu                    # List discovered names
amass db -show -d corp.lu                      # Show findings
amass enum -d corp.lu -json out.json          # JSON output
amass enum -d corp.lu -dir ./amass-out        # Custom output dir
amass viz -d3 -dir ./amass-out                # Interactive graph (HTML)

TRACK (DIFF OVER TIME)#

amass track -d corp.lu                        # Diff vs last run
amass track -d corp.lu -last 2                # Compare last 2 enums
# Useful for continuous attack-surface monitoring

EXAMPLES#

# Stealth passive footprint with API keys, saved for pipeline
amass enum -passive -d corp.lu -config config.yaml -o subs.txt

# Full active map with brute force and resolved IPs
amass enum -active -brute -w wordlist.txt -d corp.lu -ip -o assets.txt

# Discover the org's ASNs, then enumerate a netblock
amass intel -org "Corp Bank"
amass intel -asn 64500 -o netblocks.txt

# Feed Amass results into httpx/nuclei for live-host triage
amass enum -passive -d corp.lu -o subs.txt
# then: httpx -l subs.txt | nuclei -t ...

NOTES#

- Start passive for recon that does not touch the target; go active
  only within authorized scope
- API keys dramatically improve passive results - configure them
- Pipe subs.txt into SUBFINDER/HTTPX/NAABU/NUCLEI for a full pipeline
- amass track supports continuous external attack-surface monitoring
  (useful for a recurring FS client engagement)
- For LU FS clients, external asset discovery underpins DORA ICT
  risk identification and TIBER-EU reconnaissance scoping