AMASS
Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.
Interactive tool: Recon / OSINT Helper
OVERVIEW#
OWASP Amass performs in-depth attack surface mapping and asset discovery: subdomain enumeration, DNS, ASN/netblock, and graph-based correlation from passive + active sources. Modern replacement/complement to older DNS enum tools. Authorized scope only.
SUBCOMMANDS#
amass enum # Discover subdomains / assets amass intel # Collect intelligence (ASNs, orgs, whois, TLS) amass db # Query the local results graph database amass viz # Export graph visualizations amass track # Compare enumerations over time (diff)
PASSIVE ENUM (STEALTHY)#
amass enum -passive -d corp.lu # Passive only, no DNS resolve amass enum -passive -d corp.lu -o subs.txt # Save results amass enum -passive -df domains.txt # Multiple domains from file # Passive uses OSINT sources only - no direct traffic to target infra
ACTIVE ENUM#
amass enum -active -d corp.lu # Include zone transfers, certs amass enum -active -d corp.lu -brute # Add brute force amass enum -brute -w wordlist.txt -d corp.lu # Custom brute wordlist amass enum -active -d corp.lu -ip # Show resolved IPs amass enum -d corp.lu -src # Show which source found each
INTEL / ASN / ORG#
amass intel -d corp.lu # Root domain intel amass intel -org "Corp Bank" # Find ASNs by org name amass intel -asn 12345 # Enumerate an ASN amass intel -cidr 192.0.2.0/24 # Reverse from a netblock amass intel -whois -d corp.lu # Reverse whois expansion
SOURCES / API KEYS#
amass enum -list # List data sources # Config file adds API keys (Shodan, Censys, VirusTotal, SecurityTrails, # etc.) for much broader passive coverage: amass enum -passive -d corp.lu -config config.yaml
DATABASE & OUTPUT#
amass db -names -d corp.lu # List discovered names amass db -show -d corp.lu # Show findings amass enum -d corp.lu -json out.json # JSON output amass enum -d corp.lu -dir ./amass-out # Custom output dir amass viz -d3 -dir ./amass-out # Interactive graph (HTML)
TRACK (DIFF OVER TIME)#
amass track -d corp.lu # Diff vs last run amass track -d corp.lu -last 2 # Compare last 2 enums # Useful for continuous attack-surface monitoring
EXAMPLES#
# Stealth passive footprint with API keys, saved for pipeline amass enum -passive -d corp.lu -config config.yaml -o subs.txt # Full active map with brute force and resolved IPs amass enum -active -brute -w wordlist.txt -d corp.lu -ip -o assets.txt # Discover the org's ASNs, then enumerate a netblock amass intel -org "Corp Bank" amass intel -asn 64500 -o netblocks.txt # Feed Amass results into httpx/nuclei for live-host triage amass enum -passive -d corp.lu -o subs.txt # then: httpx -l subs.txt | nuclei -t ...
NOTES#
- Start passive for recon that does not touch the target; go active only within authorized scope - API keys dramatically improve passive results - configure them - Pipe subs.txt into SUBFINDER/HTTPX/NAABU/NUCLEI for a full pipeline - amass track supports continuous external attack-surface monitoring (useful for a recurring FS client engagement) - For LU FS clients, external asset discovery underpins DORA ICT risk identification and TIBER-EU reconnaissance scoping