Nicheloom

Market intelligence for builders — see what's gaining traction before it's crowded.

I built a site that maps the web from a bounty hunter's perspective

Details

External ID
47493567
Source
HN
Company
—
Product
I built a site that maps the web from a bounty hunter's perspective
Website domain
neobotnet.com
Launched
March 23, 2026
Cohort
—
Upvotes
46
Upvotes percentile
0.8290282902829028
Tags
—
Fetched at
Sept. 7, 2026, 9:26 p.m.
Updated at
Sept. 7, 2026, 9:26 p.m.

Description

I built this because I wanted my own directory of public companies running bug bounty programs — where I could see their infrastructure in one place and have a real idea of where to start poking holes.Neobotnet collects intel data from companies on HackerOne and Bugcrowd — subdomains, DNS records, web servers with status codes, indexed/crawled URLs, JS files, and exposed secrets/paths (still building this last part). The data is already there when you need it. No scans to run.Currently tracking 41 companies, 63,878 web servers, and 1.8M+ URLs.Long term I want to expand this to startups that depend on cloud infrastructure so they can see what's publicly accessible.Made a free sample with Capital One's data (and other companies) so you can see what it looks like without signing up: https://freerecon.comOriginal Page: https://neobotnet.comFeedback very welcome.

Enrichment

Theme
Hacker News clients, datasets, and tools
Vertical
Security
Function
Search & retrieval
Audience
Developer
AI stance
Not AI
Project type
Hobby / open-source project
Normalized one-liner
web mapping tool from security researcher perspective
Manually corrected
False

Could you build this?

Partial The web frontend and company directory are straightforward to build, but collecting and continuously updating reconnaissance data across thousands of bug bounty targets requires a complex distributed scanning pipeline.

What it would actually take: A complete implementation requires a pipeline using tools like sublist3r, amass, httpx, and Nuclei running on worker queues (Celery/Temporal) to scan DNS records, crawl URLs, and flag vulnerability patterns across thousands of hosts. The hard part is building rate-limiting, IP rotation, and continuous parsing infrastructure that avoids getting blocked while handling millions of scan points without massive AWS bills. It demands security reconnaissance experience and distributed data ingestion architecture.

Discussion

9 comments analyzed.

Competitors mentioned: Shodan API, Mitigata bug bounty platform

Concerns raised: Fake scarcity strategy alienates technical audience, Unclear long-term value proposition vs. Shodan, Limited differentiation from commodity scanners, URL data lacks actionable insights for security teams

Feature requests: JavaScript and API reconnaissance capabilities, Detection of sensitive parameters in URLs, Identification of services with default credentials, Client-side vulnerability detection

Competitors

Other products that read as similar to this one — 99 launches clear the similarity bar, closest 8 shown.

Attention rank: #24 of 100 (itself plus its competitors, highest first — normalized so YC and Product Hunt are compared fairly).

Launched 142 days after the earliest competitor.

Other launches for this product