Tool Comparison
Compare 26 ASM tools across categories, difficulty, and capabilities.
| Purpose | Maintenance | Links | |||
|---|---|---|---|---|---|
| Amass | Subdomain Discovery Tools | Beginner to Advanced | Comprehensive DNS enumeration and network mapping | Actively maintained | Site |
| asnmap | DNS, Ports, and Network Mapping | Intermediate | Map an organization to the IP ranges it actually owns via ASN lookup | Actively maintained | Site |
| BBOT | Frameworks and Orchestration | Advanced | Recursive OSINT and attack-surface framework that chains many modules automatically | Actively maintained | Site |
| Censys | Internet-Wide Scanning | Intermediate | Internet-wide scanning and certificate transparency | Actively maintained | Site |
| CloudEnum | Cloud Enumeration Tools | Beginner to Intermediate | Multi-cloud asset enumeration for AWS, Azure, and GCP | Actively maintained | Site |
| cloudlist | Cloud Asset Inventory | Intermediate | List assets across cloud providers using read-only credentials | Actively maintained | Site |
| DNSRecon | Specialized Tools | Intermediate | DNS enumeration and zone transfer testing | Actively maintained | Site |
| dnsx | DNS, Ports, and Network Mapping | Beginner | Fast DNS resolution, record lookup, and wildcard-aware brute forcing | Actively maintained | Site |
| ffuf | Crawling and Content Discovery | Intermediate | High-speed fuzzing for content discovery, parameters, and virtual hosts | Actively maintained | Site |
| Fierce | Specialized Tools | Beginner | Domain scanner and subdomain brute forcer | Legacy | Site |
| gau (GetAllUrls) | Crawling and Content Discovery | Beginner | Pull historically-known URLs for a domain from public archives | Actively maintained | Site |
| Gitleaks | Secret and Credential Discovery | Beginner | Detect hardcoded secrets in git history and block new ones in CI | Actively maintained | Site |
| httpx | HTTP Probing and Fingerprinting | Beginner | Probe a list of hosts for live HTTP services and fingerprint what they are | Actively maintained | Site |
| katana | Crawling and Content Discovery | Intermediate | Crawl web applications to map endpoints, parameters, and JavaScript-referenced routes | Actively maintained | Site |
| naabu | DNS, Ports, and Network Mapping | Intermediate | Fast SYN/CONNECT port scanning built for pipelines | Actively maintained | Site |
| notify | Frameworks and Orchestration | Beginner | Pipe tool output to Slack, Discord, Telegram, or a webhook | Actively maintained | Site |
| nuclei | Vulnerability Scanning | Intermediate to Advanced | Template-driven scanning for known vulnerabilities, exposures, and misconfigurations | Actively maintained | Site |
| Pacu | Cloud Enumeration Tools | Advanced | AWS exploitation framework for penetration testing | Actively maintained | Site |
| Recon-ng | OSINT and Information Gathering | Intermediate to Advanced | Full-featured reconnaissance framework | Legacy | Site |
| Scout Suite | Cloud Enumeration Tools | Intermediate to Advanced | Multi-cloud security auditing and misconfiguration detection | Actively maintained | Site |
| Shodan | Internet-Wide Scanning | Intermediate | Internet-connected device search engine | Actively maintained | Site |
| Subfinder | Subdomain Discovery Tools | Beginner | Fast passive subdomain discovery | Actively maintained | Site |
| theHarvester | OSINT and Information Gathering | Beginner | Email, subdomain, and host OSINT gathering | Actively maintained | Site |
| tlsx | HTTP Probing and Fingerprinting | Intermediate | Collect TLS certificate data at scale — issuers, SANs, expiry, and misconfiguration | Actively maintained | Site |
| TruffleHog | Secret and Credential Discovery | Intermediate | Find leaked credentials in repositories, filesystems, and cloud storage — and verify whether they still work | Actively maintained | Site |
| uncover | Frameworks and Orchestration | Beginner | Query Shodan, Censys, FOFA, and other engines from one command line | Actively maintained | Site |
Showing 26 of 26 tools