awesome-repositories.com
Blog
MCP
awesome-repositories.com

Entdecke die besten Open-Source-Repositories mit KI-gestützter Suche.

EntdeckenKuratierte SuchenOpen-Source-AlternativenSelf-hosted SoftwareBlogSitemap
ProjektMCP-ServerÜber unsRanking-MethodikPresse
RechtlichesDatenschutzAGB
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
·
OWASP avatar

OWASP/Amass

0
View on GitHub↗
14,722 Stars·2,136 Forks·Go·13 Aufrufeowasp.org/www-project-amass↗

Amass

Amass is a network attack surface mapper and reconnaissance framework designed to discover and map the external, internet-facing infrastructure of a target organization. It functions as an open source intelligence tool that identifies public network boundaries and locates hidden or forgotten subdomains to define an organization's total reachable footprint.

The project utilizes passive-source data aggregation from external APIs and public databases alongside active DNS brute-forcing and recursive subdomain expansion. It employs a graph-based asset mapping system to visualize the relationships between discovered domains and IP addresses, supported by a modular plugin system for integrating third-party discovery services.

The framework covers broader capabilities including network reconnaissance, public asset discovery, and the preparation of security audits by mapping all reachable entry points. These processes are managed through a concurrent worker pipeline to accelerate the scanning and resolution of large target sets.

Features

  • Attack Surface Mappers - Identifies and catalogs internet-facing infrastructure to assess and map an organization's total attack surface.
  • Reconnaissance Frameworks - Provides an automated suite for gathering intelligence and visualizing the reachable footprint of a target.
  • Multi-Source Data Aggregation - Aggregates asset information from multiple external APIs and public databases to identify subdomains.
  • Graph Databases - Utilizes a graph database to map and visualize the relationships between discovered domains and IP addresses.
  • Asset Discovery Tools - Automatically enumerates and inventories internet-facing infrastructure and network boundaries.
  • Attack Surface Mapping - Discovers and documents internet-facing assets to visualize the total reachable footprint of an organization.
  • Open Source Intelligence Tools - Collects and analyzes publicly available data from DNS and public records to define an attack surface.
  • Subdomain Enumeration Tools - Employs a discovery engine to find hidden subdomains using OSINT and permutation techniques.
  • Subdomain Enrichment Utilities - Automatically feeds discovered subdomains back into discovery engines to expand and refine the infrastructure map.
  • Network Reconnaissance Tools - Gathers detailed information about target networks to identify active services and potential entry points.
  • Resource Discovery Brute-Forcing - Implements automated DNS guessing using wordlists and permutation logic to find non-indexed network resources.
  • Network Security Auditing - Maps all reachable public assets to ensure total coverage of entry points for network security reviews.
  • Modular Plugin Systems - Provides a modular plugin system for integrating third-party discovery services without altering the core engine.
  • Worker Pool Models - Uses a multi-threaded worker pool model to accelerate the scanning and resolution of large target sets.
  • Network Security Tools - Tool for in-depth subdomain enumeration and network mapping.
  • OSINT Tooling - Comprehensive tool for network mapping and external attack surface discovery.
  • Reconnaissance - In-depth attack surface mapping and asset discovery.
  • Reconnaissance Tools - In-depth attack surface mapping and asset discovery.
  • Subdomain Enumeration - Performs comprehensive network mapping and external asset discovery.
  • DNS Security - Subdomain discovery via scraping, crawling, and archive analysis.
  • Domain Enumeration - Comprehensive utility for subdomain enumeration and network mapping.
  • Network Discovery and Enumeration - Tool for network mapping and external asset discovery.
  • Network Reconnaissance - Comprehensive subdomain enumeration and mapping.
  • Network Security Analysis - Performs subdomain enumeration via scraping and brute forcing.
  • Open Source Intelligence - Maps attack surfaces and discovers assets for security assessments.
  • Reconnaissance and Dorking - Perform network mapping and external asset discovery.
  • Subdomain Enumeration - In-depth attack surface mapping and asset discovery tool.

Star-Verlauf

Star-Verlauf für owasp/amassStar-Verlauf für owasp/amass

KI-Suche

Entdecke weitere awesome Repositories

Beschreibe in einfachen Worten, was du brauchst — die KI bewertet tausende kuratierte Open-Source-Projekte nach Relevanz.

Start searching with AI

Häufig gestellte Fragen

Was macht owasp/amass?

Amass is a network attack surface mapper and reconnaissance framework designed to discover and map the external, internet-facing infrastructure of a target organization. It functions as an open source intelligence tool that identifies public network boundaries and locates hidden or forgotten subdomains to define an organization's total reachable footprint.

Was sind die Hauptfunktionen von owasp/amass?

Die Hauptfunktionen von owasp/amass sind: Attack Surface Mappers, Reconnaissance Frameworks, Multi-Source Data Aggregation, Graph Databases, Asset Discovery Tools, Attack Surface Mapping, Open Source Intelligence Tools, Subdomain Enumeration Tools.

Welche Open-Source-Alternativen gibt es zu owasp/amass?

Open-Source-Alternativen zu owasp/amass sind unter anderem: aboul3la/sublist3r — Sublist3r is a subdomain enumeration tool and passive reconnaissance framework designed to discover subdomains by… projectdiscovery/subfinder — Subfinder is a security reconnaissance framework designed for subdomain enumeration and attack surface management. It… six2dez/reconftw — reconftw is an attack surface management framework and reconnaissance workflow orchestrator designed to automate the… guelfoweb/knock — Knock is an attack surface management tool and DNS reconnaissance framework used for discovering and mapping an… projectdiscovery/naabu — Naabu is a port scanner library and tool that probes hosts for open ports using SYN, CONNECT, and UDP methods to… blacklanternsecurity/bbot — This project is an open-source intelligence reconnaissance framework and recursive attack surface mapper. It functions…

Open-Source-Alternativen zu Amass

Ähnliche Open-Source-Projekte, sortiert nach der Anzahl der gemeinsamen Funktionen mit Amass.
  • aboul3la/sublist3rAvatar von aboul3la

    aboul3la/Sublist3r

    10,957Auf GitHub ansehen↗

    Sublist3r is a subdomain enumeration tool and passive reconnaissance framework designed to discover subdomains by querying search engines and public intelligence sources. It functions as a security tool for identifying the digital footprint of a target domain. The project provides both passive enumeration through multi-source API aggregation and active discovery via a DNS brute force tool. It includes a TCP port scanner to identify active services and open ports on discovered subdomains, facilitating attack surface mapping. The tool can be used as a standalone utility or as a Python security

    Python
    Auf GitHub ansehen↗10,957
  • projectdiscovery/subfinderAvatar von projectdiscovery

    projectdiscovery/subfinder

    13,105Auf GitHub ansehen↗

    Subfinder is a security reconnaissance framework designed for subdomain enumeration and attack surface management. It functions as a discovery engine that identifies and maps internet-exposed infrastructure, cloud-hosted assets, and network ranges to maintain a comprehensive inventory of an organization's digital footprint. The project distinguishes itself through a modular, template-driven scanning engine that executes security checks against discovered assets. It leverages cloud-native asset discovery to query provider APIs and infrastructure metadata, while supporting distributed agent orc

    Gobugbountyhackinghacktoberfest
    Auf GitHub ansehen↗13,105
  • six2dez/reconftwAvatar von six2dez

    six2dez/reconftw

    7,226Auf GitHub ansehen↗

    reconftw is an attack surface management framework and reconnaissance workflow orchestrator designed to automate the discovery, mapping, and monitoring of external digital assets. It operates as a modular tool-chain pipeline that coordinates a sequence of security tools to perform intelligence gathering and vulnerability scanning. The project distinguishes itself through a cloud-native deployment model that parallelizes scanning workloads across a fleet of remote VPS instances to bypass local resource constraints. It utilizes container-based environment isolation to ensure consistent executio

    Shellbug-bountybugbountybugbounty-tool
    Auf GitHub ansehen↗7,226
  • guelfoweb/knockAvatar von guelfoweb

    guelfoweb/knock

    4,163Auf GitHub ansehen↗

    Knock is an attack surface management tool and DNS reconnaissance framework used for discovering and mapping an organization's external infrastructure. It functions as a subdomain enumeration tool and HTTP security scanner to identify reachable hosts and organizational assets. The project distinguishes itself by using a passive-active hybrid enumeration strategy, combining external API lookups with active wordlist brute-force attacks and DNS zone transfers. It includes a multi-stage validation pipeline that detects DNS wildcard records and verifies host connectivity to filter out false positi

    Python
    Auf GitHub ansehen↗4,163
Alle 30 Alternativen zu Amass anzeigen→