Blog

OWASP Amass 5 First Look

With the Internet, I’ve learned that if you stop to think, you’ll miss something.

OWASP Amass has released version 5, following the long-standing version 4 that I previously reviewed in depth. Given the major version change, substantial updates were expected.

This post outlines the key differences between Amass v4 and v5, highlighting what’s new and what’s changed. In subsequent posts, I’ll examine how these updates affect practical workflows.

Key Differences at a Glance

While Amass v4 was the revolutionary pivot to the Open Asset Model (OAM), version 5 is an evolutionary step forward on that same path. In version 5:

Thoughts for a v5 Install

Like a lot of open source projects OWASP Amass has documentation issues. Moving and removing commands leaves users grasping for a path forward and that path is missing. Older and out of date information cluttered with updated documentation causes a lot of confusion and frustration. This does not serve for what is otherwise an amazing project.

My plan moving forward is to use a Neo4j data tier in a clear fresh install. My experiences will be in subsequent blogs.

← All posts