mrkeyoor.com_
Tue 06 Oct 15:52 UTC
Dev Toolsevaluationupdated 06 Oct 2026

amass review

OWASP Amass maps an organization's external attack surface by combining public data sources, DNS work, active reconnaissance, and a graph of discovered assets. It is broader than a subdomain finder: it can track domains, addresses, networks, services, certificates, organizations, and the relationships between them.

Verdict

Our Amass run installed 618 Go packages and built in 103 seconds, then finished with 22 passing and 3 failing test packages, so v5.1.1 deserves a pinned trial rather than blind rollout. Use it when you need a persistent asset graph and can own the database, credentials, scope, and active-scan policy. Choose a narrower passive tool when the output you need is simply a list of subdomains.

We ran it

Lab card: what happened when we ran amassScreenshot of amass (owasp.org/www-project-amass)
Install✓ · 58s618 packages
Build✓ · 103s
Tests✗ · 34s22 passed · 3 failed of 25 (go test)
Repo224 files~36,042 lines of source · 1.3 MB · 4 CI workflows · Dockerfile

Answers from our run

Does amass build from source?

Dependencies installed in 58 seconds (618 packages), and the build succeeded in 103 seconds. We cloned commit 79299dc into a clean Debian container with 3 CPUs and no project-specific setup.

Do amass's tests pass?

Not all of them: 22 of 25 passed and 3 failed when we ran the project's own test command (go test). Some failures need services or credentials a bare container does not have.

Who should not use amass?

Anyone who only needs a fast passive subdomain list: Amass v5 adds an engine, asset database, transformation rules, and a larger operating surface.

What are the alternatives to amass?

Subfinder, Uncover, httpx. Our Amass run installed 618 Go packages and built in 103 seconds, then finished with 22 passing and 3 failing test packages, so v5.

Setup2/5618 packages, a 103-second build, and 3 failed test packages
Docs3/5Detailed config docs, but the v5 wiki command list is stale
Community4/515,295 stars with issue and PR activity through September 2026
Maturity3/5Long-running project, but v5.1.1 has open command regressions

Who it’s for

Security teams running authorized, repeatable discovery across domains, IP ranges, and autonomous systems.
Attack-surface programs that need findings stored as related assets instead of a flat text file.
Researchers prepared to configure data-source credentials, scope boundaries, and active-scan policy.
Operators who want local SQLite for small runs and PostgreSQL or Neo4j for longer-lived deployments.

Who it’s NOT for

Anyone who only needs a fast passive subdomain list: Amass v5 adds an engine, asset database, transformation rules, and a larger operating surface.
Teams expecting the full suite to pass in a plain Go container: our run ended with 3 failed packages, including internal/libpostal at build time.
v4 users who rely on old commands without checking migration details: issue 1148 says the wiki still documents removed intel and db commands.
Workflows that depend on v5.1.1 wordlist brute force or alterations without output validation: issues 1122 and 1140 report accepted settings that produce no expected names.
Operators who cannot define authorization and egress for active probes: active enumeration touches target-visible network services.
Buyers who need one license identifier for every component: the README says some subcomponents have separate licenses.

Setup reality

Our fresh Go sandbox installed commit 79299dc in 58 seconds, pulling 618 packages. The build passed in 103 seconds. Tests failed after 34 seconds: 22 passed and 3 failed out of 25. The log tail identifies internal/libpostal as a build failure but does not show its underlying compiler error.

A local run can use the automatically created SQLite database. Production deployments may add PostgreSQL or Neo4j, an engine API, YAML scope and transformation rules, plus credentials for external data sources. Active enumeration also needs explicit authorization and an egress decision.

The module and official Dockerfile declare Go 1.26. Optional native street-address parsing uses libpostal and CGO, while the documented basic source install disables CGO. The repository includes a Dockerfile; Compose deployment lives in another repo and requires database passwords before first startup.

Amass stores an attack surface as connected assets

Amass does more than collect hostnames. Its v5 data model stores typed assets and relations, so one IP address found by several sources remains one entity with several source annotations. Scope can begin with domains, IP addresses, CIDR ranges, autonomous system numbers, and selected ports. DNS records, services, certificates, URLs, organizations, and other findings join the same graph as discovery proceeds.

That model is useful when a security team needs to ask how assets connect or compare repeated enumerations. A quick local run can let Amass create SQLite automatically. Longer-lived deployments can use PostgreSQL, while Neo4j remains an option for graph queries. Release v5.1.1 changed the asset-database interface, added the first engine REST API, and introduced a durable backlog with a bounded in-memory queue. Those are system concerns, not subdomain-list features.

What happened when we ran it

Our sandbox installed commit 79299dc in 58 seconds and pulled 618 Go packages. The checkout held 224 files, about 36,042 lines of source, and occupied 1.3 MB. The build then completed successfully in 103 seconds. We ran inside an unprivileged Debian container with 3 CPUs, 8 GB of RAM, no secrets, and a golang:1.24-bookworm base image.

The test command failed after 34 seconds. Go reported 22 passing and 3 failing packages out of 25. The supplied log tail shows successful results for the registry, backlog database, scope, formatting, enumeration, networking, DNS, HTTP, and visualization packages. It names github.com/owasp-amass/amass/v5/internal/libpostal as a build failure, then ends with FAIL. The tail does not contain the compiler or linker message, so assigning a cause would be guesswork.

This result is narrower than an end-to-end enumeration. We did not query a domain, contact a data provider, run an active probe, or compare database backends. The repository has 4 CI workflow files and a Dockerfile but no tests directory. Our run establishes that commit 79299dc installs and builds in the stated container, while its complete test command does not pass there.

Go 1.26 and libpostal split the source-build paths

The v5.1.1 module declares Go 1.26, and the official Dockerfile builds from a Go 1.26 Alpine image with CGO disabled. The documentation uses the same CGO-disabled route for a basic source install. Street-address parsing is a separate native path: it needs libpostal plus Autoconf, Automake, Make, Libtool, pkg-config, several gigabytes of libpostal data, and CGO enabled.

Open pull request 1129 proposes making that native backend opt-in because a default test run can otherwise select it when CGO is on. That report is relevant context, but it does not prove why our internal/libpostal package failed because our log tail omitted the underlying message. For a predictable deployment, use the documented CGO-disabled binary or official image unless street-address parsing is a requirement you have tested.

The asset graph brings database and credential work

Without a database URI, Amass creates SQLite in its configuration directory. PostgreSQL is the documented production choice, and Neo4j can serve graph-oriented queries. A Compose deployment adds database passwords, an engine service, mounted configuration, backups, and upgrades across several containers. Those pieces make repeated collection easier, but they also move Amass out of the disposable-command category.

External sources live in datasources.yaml. Entries may carry API keys, usernames, passwords, secrets, and cache lifetimes. Some providers work anonymously, while others need free or paid accounts. Keep those credentials out of shared scan output and separate them by account. The main config also controls scope, blacklists, active mode, transformation confidence, priorities, and time-to-live values. Misspelled unsupported options may be ignored, according to the configuration guide.

Two v5 flags can finish cleanly without doing the expected work

Issue 1122 reports that v5.1.1 accepts -brute and a wordlist, loads the words, then never uses that field in the engine. A v4 user can therefore receive a clean run without the expected dictionary guesses. Issue 1140 finds a similar boundary bug for alterations: technique settings do not cross the CLI-to-engine JSON handoff, so -alts -brute emits no altered names and exits without an error.

Open pull requests propose warnings or fixes, but a review should judge the released behavior. If brute forcing or alterations matter, place a known-answer domain in pre-deployment checks and assert that the expected candidate appears. An exit code of zero is insufficient for these paths. The same rule applies after a version upgrade because v5 moved responsibilities behind the engine API.

The v5 wiki still names commands that no longer exist

The root README is only a short project description and directs users to a separate documentation repository. That site has useful pages for Go, Docker, Compose, databases, scope, transformations, and data-source credentials. Yet open issue 1148 says the wiki user guide still lists the removed intel and db subcommands while omitting the current assoc, engine, and subs commands.

GitHub showed 15,295 stars and 243 combined open issues and pull requests on October 6, 2026. The last repository push was July 19, while issue activity continued into September and several open pull requests target v5 defects. Amass remains actively discussed, though the large queue and documentation split make version-specific verification essential. Our 3 failing packages reinforce the same decision: pin v5.1.1, test the exact workflows you depend on, and treat a successful command as the start of validation rather than the end.

Alternatives

ProjectWhat it isPick it when
SubfinderA focused passive subdomain discovery tool with multiple online sources.pick this instead when you need a fast subdomain list and do not need Amass's asset graph or active mapping.
UncoverA command-line client for finding exposed hosts through internet search engines.pick this instead when search-engine host discovery is the task and you already have a downstream asset pipeline.
httpxAn HTTP probing toolkit for checking and enriching known hosts and URLs.pick this instead when your inventory already exists and you mainly need live web-service probes.

What people are saying

  1. [github-trending] owasp-amass/amass

Sources

  1. OWASP Amass repository
  2. OWASP Amass documentation
  3. Amass v5.1.1 release
  4. v5 wordlist brute-force issue
  5. v5 alteration-settings issue
  6. Stale v5 wiki commands issue
  7. libpostal opt-in pull request

More dev tools reviews

kubescape · rea · grokbot-field-notes · abide · dsh-echocat-skill-panel · Compositor · the whole board →