Scripting OWASP Amass for a Customized Experience

No ratings

Presented at Texas Cyber Summit 2023 by

This workshop will be delivered by the founder of the OWASP Amass Project, Jeff Foley (@jeff_foley). This course targets professionals seeking precise visibility in charting an organization’s external attack surface. Utilizing the OWASP Amass Project’s open source framework, participants will learn to identify exposed online assets. While many have used basic Amass features in red teaming and other security tasks, few have maximized its potential by adding new features and data sources. This hands-on training will familiarize attendees with the Amass Engine, its extensibility, and the project’s future roadmap. Extensions will be coded in Lua, with example scripts provided for those new to the language. Additionally, the workshop will introduce users to the new Open Asset Model (OAM), which enhances the way we define and understand assets exposed on the internet. At the core of the OAM lies its ability to capture intricate relationships among different asset types, mirroring the real-world interconnectedness that exists between assets. This approach allows security professionals to identify critical attack vectors that might otherwise remain hidden. In this talk, we will walk you through how OWASP Amass users can harness the OAM’s power through simple and efficient integration with sqlite3 and PostgreSQL. Join us for an immersive session, and be among the first to explore the potential of the Open Asset Model. Unleash the true power of OWASP Amass and fortify your organization’s defense like never before!