Nicheloom

Market intelligence for builders — see what's gaining traction before it's crowded.

Thunderstorm

A collector and derivation engine. It maps your environment, evaluates effective permissions and trust, and writes a complete attack graph as a single .rage.ndjson file. The input to everything else.

Details

External ID
1370401498
Source
GITHUB
Company
—
Product
Thunderstorm
Website domain
github.com
Launched
Sept. 14, 2026
Cohort
—
Upvotes
72
Upvotes percentile
0.8895080707148347
Tags
—
Fetched at
Sept. 18, 2026, 5:02 p.m.
Updated at
Sept. 18, 2026, 5:02 p.m.

Enrichment

Theme
Vertical
Security
Function
Observability & eval
Audience
Developer
AI stance
Not AI
Project type
Hobby / open-source project
Normalized one-liner
attack graph generator for infrastructure security
Manually corrected
False

Could you build this?

No Building an attack graph derivation engine requires deep offensive security domain expertise to analyze identity permissions, ACLs, and multi-cloud trust boundaries.

What it would actually take: The engine requires high-throughput collectors querying Active Directory, Azure AD/Entra, AWS IAM, and GCP IAM APIs to ingest identity permissions into a directed graph structure. The derivation engine must compute transitive trust paths, effective access rights, and privilege escalation vectors, written in a high-performance systems language like Rust or Go with complex graph theory algorithms.

Competitors

Other products that read as similar to this one — 17 launches clear the similarity bar, closest 8 shown.

Attention rank: #2 of 18 (itself plus its competitors, highest first — normalized so YC and Product Hunt are compared fairly).

Launched 279 days after the earliest competitor.

Other launches for this product

Same idea, different domain

Nobody's really built a observability & eval tool for Media & entertainment yet.