awesome-repositories.com
Blog
MCP
awesome-repositories.com

Discover the best open-source repositories with AI-powered search.

ExploreCurated searchesOpen-source alternativesSelf-hosted softwareBlogSitemap
ProjectMCP serverAboutHow we rankPress
LegalPrivacyTerms
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
owasp-amass avatar

owasp-amass/amass

0
View on GitHub↗
14,155 stars·2,083 forks·Go·other·29 viewsowasp.org/www-project-amass↗

Amass

Amass is an attack surface management tool designed to identify, map, and inventory an organization's internet-facing digital assets. It functions as a security asset discovery engine that systematically expands an organization's known infrastructure footprint through recursive domain name resolution and the collection of intelligence from diverse public data sources.

The platform distinguishes itself by utilizing a graph-based modeling approach to organize discovered resources. By maintaining a persistent graph database, it tracks the relationships between infrastructure components and normalizes data from multiple intelligence feeds into a unified schema. This allows for the visualization of complex network topologies and the long-term monitoring of infrastructure changes.

The framework supports comprehensive security visibility by integrating modular data collection tasks and asynchronous processing to handle large-scale network scanning. It provides a centralized repository for asset records, enabling consistent tracking and analysis of an entity's technical landscape for threat intelligence and vulnerability identification.

Features

  • Attack Surface Management - Provides a platform for mapping organizational digital assets to identify security vulnerabilities across the network.
  • DNS Reconnaissance - Discovers subdomains and network resources by querying public data sources and performing recursive DNS lookups.
  • Asset Discovery Tools - Tracks and models relationships between infrastructure components to maintain a comprehensive view of the attack surface.
  • Asset Inventory Management - Maintains a searchable database of discovered resources to track infrastructure changes across multiple environments.
  • Threat Intelligence Platforms - Aggregates and analyzes external infrastructure data to proactively identify vulnerabilities and potential entry points.
  • Command Line Tools - Listed in the “Command Line Tools” section of the The Book Of Secret Knowledge awesome list.
  • Reconnaissance and Discovery - In-depth attack surface mapping and asset discovery tool.
  • Reconnaissance Tools - Tool for in-depth DNS enumeration and network mapping.
  • Subdomain Discovery - Performs brute force enumeration and searches web archives.
  • Open Source Intelligence - Tool for in-depth attack-surface mapping and asset discovery.
  • Security And Privacy - Framework for attack surface mapping and asset discovery.
  • Security Tools - Tool for in-depth domain reconnaissance
  • Vulnerability Scanning - DNS subdomain enumeration and network mapping tool.
  • Graph Databases - Maintains a persistent graph database to track historical states and relationships of discovered assets.
  • Topology Visualizers - Visualizes relationships between digital resources to map complex network topologies and service interactions.
  • Asset Record Repositories - Provides a centralized repository for asset records to ensure consistent tracking and long-term infrastructure monitoring.
  • Recursive DNS Resolvers - Performs recursive DNS resolution to systematically discover subdomains and expand the known infrastructure footprint.
  • Graph-Based Modeling - Organizes discovered infrastructure into a connected graph of nodes and edges to map complex resource relationships.
  • Data Normalization and Schema Enforcement - Standardizes disparate intelligence data into a unified schema for consistent analysis and reporting.
  • Relationship Modeling - Links resource types and properties within a structured model to visualize interactions across the technical landscape.
  • Data Ingestion Plugins - Executes modular enumeration tasks through independent plugins to gather intelligence from diverse external sources.

Star history

Star history chart for owasp-amass/amassStar history chart for owasp-amass/amass

How this analysis was created: This summary and feature list are AI-generated from collected project material and can contain mistakes. Stars, license and language are imported from GitHub. Inclusion does not mean that we have tested or audited this project. Check the source documentation for any feature you depend on. Learn more on our About page.

AI search

Explore more awesome repositories

Describe what you need in plain English — the AI ranks thousands of curated open-source projects by relevance.

Start searching with AI

Projects sharing features with Amass

These projects share indexed features with Amass. Shared tags can include platform or build tooling; verify the primary use case before treating a result as a replacement.
  • projectdiscovery/subfinderprojectdiscovery avatar

    projectdiscovery/subfinder

    13,105View on GitHub↗

    Subfinder is a security reconnaissance framework designed for subdomain enumeration and attack surface management. It functions as a discovery engine that identifies and maps internet-exposed infrastructure, cloud-hosted assets, and network ranges to maintain a comprehensive inventory of an organization's digital footprint. The project distinguishes itself through a modular, template-driven scanning engine that executes security checks against discovered assets. It leverages cloud-native asset discovery to query provider APIs and infrastructure metadata, while supporting distributed agent orc

    Gobugbountyhackinghacktoberfest
    View on GitHub↗13,105
  • smicallef/spiderfootsmicallef avatar

    smicallef/spiderfoot

    18,189View on GitHub↗

    SpiderFoot is an open-source reconnaissance and intelligence automation framework designed to streamline the collection and correlation of data for security investigations. It functions as a comprehensive platform that automates the querying of hundreds of public data sources to map digital footprints, identify exposed assets, and uncover potential security threats across an organization's external perimeter. The platform distinguishes itself through a modular, plugin-based architecture that executes data gathering tasks in parallel, supported by a directed graph data model that tracks relati

    Pythonattacksurfacecticybersecurity
    View on GitHub↗18,189
  • projectdiscovery/nucleiprojectdiscovery avatar

    projectdiscovery/nuclei

    29,189View on GitHub↗

    Nuclei is a modular security scanning framework designed for automated vulnerability detection and infrastructure reconnaissance. It functions as a template-driven engine that executes security checks across diverse network protocols, allowing users to define custom detection logic to identify vulnerabilities, misconfigurations, and exposed assets. The platform distinguishes itself through its highly extensible architecture, which supports distributed scanning, headless browser automation for dynamic web content, and out-of-band interaction monitoring to detect blind vulnerabilities. It integ

    Goattack-surfacecve-scannerdast
    View on GitHub↗29,189
  • 1n3/sn1per1N3 avatar

    1N3/Sn1per

    10,049View on GitHub↗

    Sn1per is a vulnerability management platform and penetration testing orchestrator designed to automate reconnaissance, vulnerability scanning, and exploit verification. It functions as a dockerized security toolkit that coordinates multiple tools into a unified automated pipeline to identify security flaws across network and web assets. The platform features an attack surface manager for discovering internet-facing assets through OSINT, DNS enumeration, and certificate transparency. It distinguishes itself with an AI-powered security analyzer that uses large language models to summarize scan

    Shellattack-surfaceattack-surface-managementattacksurface
    View on GitHub↗10,049
Compare all 30 related projects→

Frequently asked questions

What does owasp-amass/amass do?

Amass is an attack surface management tool designed to identify, map, and inventory an organization's internet-facing digital assets. It functions as a security asset discovery engine that systematically expands an organization's known infrastructure footprint through recursive domain name resolution and the collection of intelligence from diverse public data sources.

What are the main features of owasp-amass/amass?

The main features of owasp-amass/amass are: Attack Surface Management, DNS Reconnaissance, Asset Discovery Tools, Asset Inventory Management, Threat Intelligence Platforms, Command Line Tools, Reconnaissance and Discovery, Reconnaissance Tools.

Which projects share features with owasp-amass/amass?

Projects with overlapping indexed features include: projectdiscovery/subfinder — Subfinder is a security reconnaissance framework designed for subdomain enumeration and attack surface management. It… smicallef/spiderfoot — SpiderFoot is an open-source reconnaissance and intelligence automation framework designed to streamline the… projectdiscovery/nuclei — Nuclei is a modular security scanning framework designed for automated vulnerability detection and infrastructure… 1n3/sn1per — Sn1per is a vulnerability management platform and penetration testing orchestrator designed to automate… blacklanternsecurity/bbot — This project is an open-source intelligence reconnaissance framework and recursive attack surface mapper. It functions… six2dez/reconftw — reconftw is an attack surface management framework and reconnaissance workflow orchestrator designed to automate the…