OWASP Amass: Advanced Subdomain Enumeration
OWASP Amass is a powerful and versatile open-source tool for network reconnaissance, specifically designed for extensive attack surface mapping and external asset discovery. Its primary function is subdomain enumeration, but it also provides capabilities for finding associated IP addresses, ASNs (Autonomous System Numbers), Whois data, and more. Effective subdomain enumeration is crucial for penetration testers and bug bounty hunters to uncover hidden assets and potential entry points into a target organization’s infrastructure.
Basic Subdomain Enumeration
The amass enum subcommand is used for performing enumeration.
amass enum -d <domain.com>
# Example:
amass enum -d example.com-d <domain.com>: Specifies the target domain for enumeration.
Enumeration with ASN (Autonomous System Number)
You can specify an ASN to limit the scope of your enumeration to assets belonging to a particular organization’s network block. This is useful for focusing on a specific part of a larger network.
amass enum -asn <ASN_NUMBER> -d <domain.com>
# Example: Targeting LACNIC.net within ASN 28000
amass enum -asn 28000 -d lacnic.net-asn <ASN_NUMBER>: Filters results to show only subdomains associated with this Autonomous System Number.
Other Useful amass enum Options
- Passive Enumeration (Default): Amass primarily uses passive sources (like DNS records, public databases, search engines) which generate no traffic to the target.
- Active Enumeration (
-active): Performs DNS brute-forcing, permutations, and active probing (sends traffic to the target). Use with caution and explicit permission.amass enum -active -d example.com - Specify Data Sources (
-src): You can limit the data sources Amass uses.amass enum -d example.com -src virus_total,shodan - Output to File (
-o): Save the enumeration results to a file.amass enum -d example.com -o example_subdomains.txt - IP Addresses (
-ip): Include IP addresses for the discovered subdomains.amass enum -d example.com -ip
Disclaimer: Amass is a powerful reconnaissance tool. Its use should be restricted to legal and ethical purposes, such as authorized penetration testing, bug bounty hunting on explicitly allowed scopes, or personal research on domains you own. Unauthorized scanning and enumeration of networks are illegal and unethical.