OWASP Amass on Ubuntu 24.04 LTS

Azure Security

OWASP Amass, the open source attack surface mapping and external asset discovery tool, ready to enumerate the subdomains, DNS records and certificates of the domains you own the moment you log in.

Base
Hardened build
minimal ports, security patches applied at build time
Access
Unique credentials
generated on first boot, readable only by root
Verified
Boots working
services pass a health gate before release
Support
24/7, 365 days
by email and live chat, 24 hour response SLA

Overview

OWASP Amass is the OWASP Foundation's flagship tool for attack surface mapping and external asset discovery. Pointed at a domain you own, it discovers the subdomains, DNS records, TLS certificates, netblocks and autonomous systems that make up your external attack surface, drawing on open source intelligence from certificate transparency logs, passive DNS, WHOIS and RDAP and more than sixty data sources. Findings are stored in an Open Asset Model asset database so results accumulate over time and can be queried and correlated, and its passive default mode collects intelligence without sending any packets to your targets.

It suits security teams, penetration testers and platform owners who need to understand and monitor the external footprint of the domains and organisations they are responsible for, whether for an ad hoc assessment or an ongoing, scheduled review.

Why the cloudimg image

cloudimg delivers Amass fully installed on a hardened, fully patched Ubuntu base, verified against the project's official published checksums before install. The image ships a ready to use configuration, an OSINT data source API key template you fill in to unlock the full source set, a persistent asset database and a daily scheduled passive enumeration that writes reports for CI or SIEM pickup. There is no listening service and no baked credential to manage: the instance is a self contained enumeration host you SSH into and point at your own domains. The base keeps receiving unattended security updates, and every deployment is paired with a step by step deploy guide and backed by 24/7 cloudimg support.

Common uses

  • External attack surface mapping
  • Subdomain and asset discovery
  • Scheduled OSINT reconnaissance