Back to Talks 2023
Talk

Unlocking the Power of OWASP Amass: Introducing the Open Asset Model for Comprehensive Attack Surface Mapping

Recon Village @ DEF CON 3111th, 12th and 13th August 2023

Abstract

Are you ready to take your attack surface mapping to the next level? Join us at Recon Village as we unveil the game-changing integration of the Open Asset Model into the OWASP Amass Project v4.0!

The Open Asset Model (OAM) enhances the way we define and understand assets exposed on the internet. Traditionally, asset specifications have been confined to technical, infrastructure-specific details. However, this narrow approach limits organizations' ability to grasp the full scope of their attack surface. The OAM breaks these barriers, enabling users to encompass both digital and physical assets, empowering organizations to see the bigger picture.

At the core of the OAM lies its ability to capture intricate relationships among different asset types, mirroring the real-world interconnectedness that exists between assets. This approach allows security professionals to identify critical attack vectors that might otherwise remain hidden.

In this talk, we will walk you through how OWASP Amass users can harness the OAM's power through simple and efficient integration with sqlite3 and PostgreSQL. Join us for an immersive session, and be among the first to explore the potential of the Open Asset Model. Unleash the true power of OWASP Amass and fortify your organization's defense like never before!

Speaker

Jeff Foley
Jeff Foley

Amass Project Leader, OWASP Foundation

Jeff Foley has over 20 years of industry experience focused on research & development and security assessment. He is the Vice Chairman for the OWASP Projects Committee. He is also the Project Leader for Amass, an OWASP Foundation Flagship Project that performs in-depth attack surface mapping and asset discovery. Previously, he served as the Vice President of Attack Surface Protection for ZeroFox. Jeff was also the Global Head of Attack Surface Management at Citi. Prior to this, Jeff served as the Program Manager for Offensive Cyber Warfare Research & Development at Northrop Grumman Corporation. In his spare time, Jeff enjoys giving back to the information security community.

View full speaker profile →