Tool profile
OWASP Amass
Map an authorized organization's external asset footprint
Claims and corrections are reviewed before public profile changes.
Trust / disclosure
How to read this profile
Editorial line
Editorial judgment and commercial context are kept separate on OSINT4ALL.
Review status
This profile has an editorial review date. Source checking does not mean the tool was hands-on tested.
Claims / submissions
Corrections and claim requests are reviewed before any public change is made.
Commercial context
No commercial relationship is disclosed on this profile.
Editorial verdict
Use case and fit
This is editorial guidance, not vendor copy.
Structured discovery of domains and related infrastructure for a clearly scoped asset inventory.
Some modes contact target infrastructure. Do not describe all operation as passive.
Best for structured discovery of domains and related infrastructure for a clearly scoped asset inventory.
Operational snapshot
Workflow, access, and coverage
DNS and domain infrastructure intelligence, Certificate transparency intelligence, Passive reconnaissance automation
Domain, Hostname, IP Address, Organization, Certificate
DNS Record, Subdomain, Nameserver History, Infrastructure Link, Certificate Record
Discovery, Enrichment, Pivoting, Verification
Define written scope; start with passive sources; record dates and provenance; remove shared infrastructure; corroborate ownership; use active methods only when explicitly authorized.
English-first editorial profile. Verify current interface languages and source-language coverage; multilingual input does not guarantee equal analytical quality.
Limits
Strengths, caveats, and risk
Combines discovery and relationship modeling in a repeatable technical workflow.
Configuration, upstream data sources and active versus passive modes require care.
Discovered relationships do not prove ownership, current control or vulnerability.
Discovered relationships do not prove ownership, current control or vulnerability.
Keep work within authorized scope; no credential use, exploitation or intrusive probing without explicit permission.
Dated infrastructure observations do not establish ownership, compromise or attribution. Official-source desk research only; not hands-on tested. Tool-specific caution: Discovered relationships do not prove ownership, current control or vulnerability.
Maintenance
Source status & suggest an update
Help keep this profile accurate. Update requests are reviewed and logged before publication.
Source checked: 2026-09-19
If something is outdated, please submit a correction or ownership update request. Claim requests are reviewed and do not grant editorial control.
Commercial or sponsorship requests use the separate partner workflow.