owasp-amass/amass

In-depth attack surface mapping and asset discovery

View on GitHub ↗Jump to charts ↓

Summary Information

Updated 33 minutes ago
Added to GitGenius on September 3rd, 2026
Created on July 10th, 2018
Open Issues & Pull Requests: 242 (+0)
GitHub issues: Enabled
Number of forks: 2,180
Total Stargazers: 15,118 (+0)
Total Subscribers: 225 (+0)

Repository Insights (GitGenius)

Median issue/PR response: 7.6 days
Mean response time: 135.0 days
90th percentile: 261.3 days
Tracked items: 75

How this project is maintained

Around half of the issues opened in the past year never receive a reply. 100% of open issues come from outside the core team, so the backlog reflects real-world use rather than internal planning. Only 7% of issues opened in the past year have been closed. Three people close 77% of everything that gets resolved.

Charts & Analytics

Fetching additional details & charts...

Issue Activity (beta)

Open issues: 57
New in 7 days: 0
Closed in 7 days: 0
Avg open age: 533 days
Stale 30+ days: 56
Stale 90+ days: 53

Recent activity

Opened in 7 days: 0
Closed in 7 days: 0
Comments in 7 days: 0
Events in 7 days: 0

Top labels

No label distribution available yet.

Most active issues this week

No issue events were indexed in the last 7 days.

Detailed Description

OWASP Amass is a command-line tool for in-depth attack surface mapping and external asset discovery using open source information gathering and active reconnaissance techniques.

The tool addresses the problem of identifying an organization's exposed digital footprint by combining passive and active reconnaissance methods. It performs network mapping to uncover subdomains, IP addresses, and other assets associated with a target domain or organization. The approach integrates multiple data sources and reconnaissance techniques to build a comprehensive picture of an attack surface.

Organizations conducting security assessments, penetration testing, or asset inventory work should consider this tool. It suits teams that need systematic, automated discovery of external-facing infrastructure and want to understand their exposure before attackers do. The tool is available through multiple installation channels and integrates with other security platforms like Maltego.

The project maintains active test coverage and accepts community contributions through a dedicated Discord server where users can discuss goals and get support. The codebase is written in Go, making it portable across platforms.