Amass stores an attack surface as connected assets
Amass does more than collect hostnames. Its v5 data model stores typed assets and relations, so one IP address found by several sources remains one entity with several source annotations. Scope can begin with domains, IP addresses, CIDR ranges, autonomous system numbers, and selected ports. DNS records, services, certificates, URLs, organizations, and other findings join the same graph as discovery proceeds.
That model is useful when a security team needs to ask how assets connect or compare repeated enumerations. A quick local run can let Amass create SQLite automatically. Longer-lived deployments can use PostgreSQL, while Neo4j remains an option for graph queries. Release v5.1.1 changed the asset-database interface, added the first engine REST API, and introduced a durable backlog with a bounded in-memory queue. Those are system concerns, not subdomain-list features.
What happened when we ran it
Our sandbox installed commit 79299dc in 58 seconds and pulled 618 Go packages. The checkout held 224 files, about 36,042 lines of source, and occupied 1.3 MB. The build then completed successfully in 103 seconds. We ran inside an unprivileged Debian container with 3 CPUs, 8 GB of RAM, no secrets, and a golang:1.24-bookworm base image.
The test command failed after 34 seconds. Go reported 22 passing and 3 failing packages out of 25. The supplied log tail shows successful results for the registry, backlog database, scope, formatting, enumeration, networking, DNS, HTTP, and visualization packages. It names github.com/owasp-amass/amass/v5/internal/libpostal as a build failure, then ends with FAIL. The tail does not contain the compiler or linker message, so assigning a cause would be guesswork.
This result is narrower than an end-to-end enumeration. We did not query a domain, contact a data provider, run an active probe, or compare database backends. The repository has 4 CI workflow files and a Dockerfile but no tests directory. Our run establishes that commit 79299dc installs and builds in the stated container, while its complete test command does not pass there.
Go 1.26 and libpostal split the source-build paths
The v5.1.1 module declares Go 1.26, and the official Dockerfile builds from a Go 1.26 Alpine image with CGO disabled. The documentation uses the same CGO-disabled route for a basic source install. Street-address parsing is a separate native path: it needs libpostal plus Autoconf, Automake, Make, Libtool, pkg-config, several gigabytes of libpostal data, and CGO enabled.
Open pull request 1129 proposes making that native backend opt-in because a default test run can otherwise select it when CGO is on. That report is relevant context, but it does not prove why our internal/libpostal package failed because our log tail omitted the underlying message. For a predictable deployment, use the documented CGO-disabled binary or official image unless street-address parsing is a requirement you have tested.
The asset graph brings database and credential work
Without a database URI, Amass creates SQLite in its configuration directory. PostgreSQL is the documented production choice, and Neo4j can serve graph-oriented queries. A Compose deployment adds database passwords, an engine service, mounted configuration, backups, and upgrades across several containers. Those pieces make repeated collection easier, but they also move Amass out of the disposable-command category.
External sources live in datasources.yaml. Entries may carry API keys, usernames, passwords, secrets, and cache lifetimes. Some providers work anonymously, while others need free or paid accounts. Keep those credentials out of shared scan output and separate them by account. The main config also controls scope, blacklists, active mode, transformation confidence, priorities, and time-to-live values. Misspelled unsupported options may be ignored, according to the configuration guide.
Two v5 flags can finish cleanly without doing the expected work
Issue 1122 reports that v5.1.1 accepts -brute and a wordlist, loads the words, then never uses that field in the engine. A v4 user can therefore receive a clean run without the expected dictionary guesses. Issue 1140 finds a similar boundary bug for alterations: technique settings do not cross the CLI-to-engine JSON handoff, so -alts -brute emits no altered names and exits without an error.
Open pull requests propose warnings or fixes, but a review should judge the released behavior. If brute forcing or alterations matter, place a known-answer domain in pre-deployment checks and assert that the expected candidate appears. An exit code of zero is insufficient for these paths. The same rule applies after a version upgrade because v5 moved responsibilities behind the engine API.
The v5 wiki still names commands that no longer exist
The root README is only a short project description and directs users to a separate documentation repository. That site has useful pages for Go, Docker, Compose, databases, scope, transformations, and data-source credentials. Yet open issue 1148 says the wiki user guide still lists the removed intel and db subcommands while omitting the current assoc, engine, and subs commands.
GitHub showed 15,295 stars and 243 combined open issues and pull requests on October 6, 2026. The last repository push was July 19, while issue activity continued into September and several open pull requests target v5 defects. Amass remains actively discussed, though the large queue and documentation split make version-specific verification essential. Our 3 failing packages reinforce the same decision: pin v5.1.1, test the exact workflows you depend on, and treat a successful command as the start of validation rather than the end.

