OSINT
OWASP Amass
In-depth attack surface mapping and subdomain discovery.
Authorized testing only. Practice on systems you own, isolated labs, or targets with written permission. Unauthorized access is illegal.
When
Building a complete external asset inventory for a domain in scope.
How
Run enum in passive then active modes; visualize with graph; feed into scanners.
Why
One of the most thorough open-source subdomain/asset mappers.
Commands & usage
amass enum -passive -d example.com -o amass.txt
amass enum -active -d example.com -brute
amass viz -d3 -d example.com
Commands are educational examples. Adapt hosts, paths, and rates to your authorized scope.
Tags
Related in OSINT
Maltego
Graph-based link analysis for people, domains, infrastructure, and relationships.
theHarvester
Gathers emails, subdomains, hosts, and employee names from public sources.
Recon-ng
Modular recon framework with workspace DB and API-backed modules.
SpiderFoot
Automated OSINT scanner with web UI covering 200+ data sources.
Sherlock
Hunt usernames across hundreds of social sites.
Maigret
Username OSINT tool with report generation across many sites.