Software Alternatives & Reviews

w3af VS OWASP Amass

Compare w3af VS OWASP Amass and see what are their differences

w3af logo w3af

w3af is a Web Application Attack and Audit Framework

OWASP Amass logo OWASP Amass

An advanced open source tool to help information security professionals perform network mapping of attack surfaces and external asset discovery using open source information gathering and active reconnaissance techniques!
  • w3af Landing page
    Landing page //
    2018-09-29
  • OWASP Amass Landing page
    Landing page //
    2021-08-14

w3af videos

How to use the w3af website scanner in kali Linux

More videos:

  • Tutorial - What is W3af? | How to install Web Application Attack & Audit Framework?
  • Tutorial - W3AF Tutorial Part II using the GUI

OWASP Amass videos

LevelUp 0x04 - OWASP Amass – Discovering Internet Exposure

More videos:

  • Review - Jeff Foley - Advanced Recon with OWASP Amass video - DEF CON 27 Recon Village
  • Review - OWASP Amass Red Team Village Training - by Jeff Foley (Cafffix)

Category Popularity

0-100% (relative to w3af and OWASP Amass)
Web Application Security
75 75%
25% 25
Security
68 68%
32% 32
Cyber Security
35 35%
65% 65
Monitoring Tools
75 75%
25% 25

User comments

Share your experience with using w3af and OWASP Amass. For example, how are they different and which one is better?
Log in or Post with

Social recommendations and mentions

OWASP Amass might be a bit more popular than w3af. We know about 1 link to it since March 2021 and only 1 link to w3af. We are tracking product recommendations and mentions on various public social media platforms and blogs. They can help you identify which product is more popular and what people think of it.

w3af mentions (1)

  • 3 reasons why any website's security is important
    Testing security of your website is easy. There are dozen of web security testing tools out there you can use for free. Arachni and w3af are famous open source security scanners you can use. - Source: dev.to / over 1 year ago

OWASP Amass mentions (1)

  • OWASP Amass
    The Amass tool is a perfect fit for the sub-techniques in the Search Open Technical Databases category which is part of the reconnaissance phase from the matrix above. - Source: dev.to / 3 days ago

What are some alternatives?

When comparing w3af and OWASP Amass, you can also consider the following products

Nikto - Nikto is an Open Source (GPL) web server scanner which performs comprehensive tests against web...

Sublist3r - Sublist3r is a python tool designed to enumerate subdomains of websites using OSINT.

Burp Suite - Burp Suite is an integrated platform for performing security testing of web applications.

SpiderFoot - Open source intelligence (OSINT) automation tool.

Acunetix - Audit your website security and web applications for SQL injection, Cross site scripting and other...

sn0int - sn0int is a semi-automatic OSINT framework and package manager