Security tool · recon

amass

In-depth attack-surface mapping and asset discovery. Slower and heavier than subfinder but finds more via active enumeration and its graph DB.

subdomainspassiveactiveowaspgraph
Stable IDtool:amassLast updatedLast verifiedLegacy review pendingProvenanceSource-linked

Where amass fits

In-depth attack-surface mapping and asset discovery. Slower and heavier than subfinder but finds more via active enumeration and its graph DB.

Detection-first use

Start with the least intrusive template that can distinguish your hypothesis from a normal response. Preserve raw output and a negative control.

Installation references

Install with goAuthorization required
go install -v github.com/owasp-amass/amass/v4/...@master
Positive signal
Tool-specific output that supports the stated hypothesis.
Negative control
No result, or identical behavior against a known-safe control.
Intrusiveness
Review flags and target scope before execution.
Install with brewAuthorization required
brew install amass
Positive signal
Tool-specific output that supports the stated hypothesis.
Negative control
No result, or identical behavior against a known-safe control.
Intrusiveness
Review flags and target scope before execution.
Install with snapAuthorization required
sudo snap install amass
Positive signal
Tool-specific output that supports the stated hypothesis.
Negative control
No result, or identical behavior against a known-safe control.
Intrusiveness
Review flags and target scope before execution.

Command templates

Passive enumAuthorization required

Populate placeholders only with assets that are explicitly in scope.

amass enum -passive -d {domain} -o {output}
Positive signal
Tool-specific output that supports the stated hypothesis.
Negative control
No result, or identical behavior against a known-safe control.
Intrusiveness
Review flags and target scope before execution.
Active + bruteAuthorization required

Populate placeholders only with assets that are explicitly in scope.

amass enum -active -brute -d {domain} -o {output}
Positive signal
Tool-specific output that supports the stated hypothesis.
Negative control
No result, or identical behavior against a known-safe control.
Intrusiveness
Review flags and target scope before execution.

Continue the workflow

Attribution and verification

Version history: normalized permanent page created 2026-08-20. Upstream activity and popularity are separate signals and do not establish tool safety.