Skip to main content
ASM Cheatsheet

Tool Comparison

Compare 26 ASM tools across categories, difficulty, and capabilities.

PurposeMaintenanceLinks
Amass
Subdomain Discovery Tools
Beginner to Advanced
Comprehensive DNS enumeration and network mapping
Actively maintained
Site
asnmap
DNS, Ports, and Network Mapping
Intermediate
Map an organization to the IP ranges it actually owns via ASN lookup
Actively maintained
Site
BBOT
Frameworks and Orchestration
Advanced
Recursive OSINT and attack-surface framework that chains many modules automatically
Actively maintained
Site
Censys
Internet-Wide Scanning
Intermediate
Internet-wide scanning and certificate transparency
Actively maintained
Site
CloudEnum
Cloud Enumeration Tools
Beginner to Intermediate
Multi-cloud asset enumeration for AWS, Azure, and GCP
Actively maintained
Site
cloudlist
Cloud Asset Inventory
Intermediate
List assets across cloud providers using read-only credentials
Actively maintained
Site
DNSRecon
Specialized Tools
Intermediate
DNS enumeration and zone transfer testing
Actively maintained
Site
dnsx
DNS, Ports, and Network Mapping
Beginner
Fast DNS resolution, record lookup, and wildcard-aware brute forcing
Actively maintained
Site
ffuf
Crawling and Content Discovery
Intermediate
High-speed fuzzing for content discovery, parameters, and virtual hosts
Actively maintained
Site
Fierce
Specialized Tools
Beginner
Domain scanner and subdomain brute forcer
Legacy
Site
gau (GetAllUrls)
Crawling and Content Discovery
Beginner
Pull historically-known URLs for a domain from public archives
Actively maintained
Site
Gitleaks
Secret and Credential Discovery
Beginner
Detect hardcoded secrets in git history and block new ones in CI
Actively maintained
Site
httpx
HTTP Probing and Fingerprinting
Beginner
Probe a list of hosts for live HTTP services and fingerprint what they are
Actively maintained
Site
katana
Crawling and Content Discovery
Intermediate
Crawl web applications to map endpoints, parameters, and JavaScript-referenced routes
Actively maintained
Site
naabu
DNS, Ports, and Network Mapping
Intermediate
Fast SYN/CONNECT port scanning built for pipelines
Actively maintained
Site
notify
Frameworks and Orchestration
Beginner
Pipe tool output to Slack, Discord, Telegram, or a webhook
Actively maintained
Site
nuclei
Vulnerability Scanning
Intermediate to Advanced
Template-driven scanning for known vulnerabilities, exposures, and misconfigurations
Actively maintained
Site
Pacu
Cloud Enumeration Tools
Advanced
AWS exploitation framework for penetration testing
Actively maintained
Site
Recon-ng
OSINT and Information Gathering
Intermediate to Advanced
Full-featured reconnaissance framework
Legacy
Site
Scout Suite
Cloud Enumeration Tools
Intermediate to Advanced
Multi-cloud security auditing and misconfiguration detection
Actively maintained
Site
Shodan
Internet-Wide Scanning
Intermediate
Internet-connected device search engine
Actively maintained
Site
Subfinder
Subdomain Discovery Tools
Beginner
Fast passive subdomain discovery
Actively maintained
Site
theHarvester
OSINT and Information Gathering
Beginner
Email, subdomain, and host OSINT gathering
Actively maintained
Site
tlsx
HTTP Probing and Fingerprinting
Intermediate
Collect TLS certificate data at scale — issuers, SANs, expiry, and misconfiguration
Actively maintained
Site
TruffleHog
Secret and Credential Discovery
Intermediate
Find leaked credentials in repositories, filesystems, and cloud storage — and verify whether they still work
Actively maintained
Site
uncover
Frameworks and Orchestration
Beginner
Query Shodan, Censys, FOFA, and other engines from one command line
Actively maintained
Site

Showing 26 of 26 tools