OWASP Amass, the open source attack surface mapping and external asset discovery tool, ready to enumerate the subdomains, DNS records and certificates of the domains you own the moment you log in.
OWASP Amass is the OWASP Foundation's flagship tool for attack surface mapping and external asset discovery. Pointed at a domain you own, it discovers the subdomains, DNS records, TLS certificates, netblocks and autonomous systems that make up your external attack surface, drawing on open source intelligence from certificate transparency logs, passive DNS, WHOIS and RDAP and more than sixty data sources. Findings are stored in an Open Asset Model asset database so results accumulate over time and can be queried and correlated, and its passive default mode collects intelligence without sending any packets to your targets.
It suits security teams, penetration testers and platform owners who need to understand and monitor the external footprint of the domains and organisations they are responsible for, whether for an ad hoc assessment or an ongoing, scheduled review.
cloudimg delivers Amass fully installed on a hardened, fully patched Ubuntu base, verified against the project's official published checksums before install. The image ships a ready to use configuration, an OSINT data source API key template you fill in to unlock the full source set, a persistent asset database and a daily scheduled passive enumeration that writes reports for CI or SIEM pickup. There is no listening service and no baked credential to manage: the instance is a self contained enumeration host you SSH into and point at your own domains. The base keeps receiving unattended security updates, and every deployment is paired with a step by step deploy guide and backed by 24/7 cloudimg support.