Try “car wash”, “subscription box”, “Austin” · Esc to close

Neobotnet

Bug bounty infrastructure directory for security researchers

SaaS Professional services Show HN · launch post · ▲ 46

Visit site

neobotnet.com

What it does

Neobotnet aggregates infrastructure data for companies that run public bug bounty programs. It collects subdomains, DNS records, web servers with HTTP status codes, crawled URLs, JavaScript files, and partial data on exposed secrets and paths. The data comes from HackerOne and Bugcrowd listings rather than fresh scans. A security researcher can log in and browse this pre-compiled intelligence across tracked targets.

Who it is for

Security researchers and bug bounty hunters who want a central place to study the attack surface of known bug bounty targets. Instead of running their own reconnaissance tools, they can see what infrastructure is already documented and indexed across multiple companies.

Pricing

The site does not show prices.

How it stands out

Neobotnet's main advantage is convenience. It consolidates reconnaissance data that researchers would normally have to gather themselves using separate tools like Shodan, Censys, or manual subdomain enumeration. The homepage shows 5 tracked companies, 12,000 web servers, and 500,000 URLs in the public demo, suggesting the dataset is non-trivial. By focusing only on authorized bug bounty targets from official platforms, it avoids legal friction that might arise from scanning non-consenting companies. The display of "vulnerability signals"—examples like unprotected redirect URIs, numeric user IDs, and exposed JWT tokens—shows the tool highlights common weakness patterns researchers care about.

What a founder should check

First, verify the moat. Bug bounty programs already list their scope on HackerOne and Bugcrowd; Neobotnet essentially repackages publicly available metadata. Competitors could build similar aggregators relatively quickly, and larger bug bounty platforms might offer this feature natively to retain users. Second, examine switching costs and stickiness. If researchers find the data useful but discover they still need to supplement it with their own scans and tools, adoption may plateau. The value prop depends on coverage breadth and freshness—if the tool only tracks 5 companies, many researchers will need other options anyway. Third, understand pricing pressure. Security professionals often have tight budgets and access to free tools; a paid product needs to demonstrate clear time savings or significantly better data quality than free alternatives.

Thinking of building something like this?

Every launch here is a competitor to somebody's idea. If yours is close, check it against the market before you build: the Full Check names the rivals, the prices and the gaps.

Check an idea like this

More saas launches

All

Meihus

Mortgage calculator showing early payment impact with international loan flexibility

SaaS SaaS & softwareShow HN ▲ 20

GYST

Digital organizer merging file explorer, whiteboard, notes and design tools

SaaS SaaS & softwareShow HN ▲ 37

Checked ideas in Professional services

Fractional HR for Seoul startups under 50 people Kill

Monthly HR retainer (contracts, onboarding, compliance) for Seoul startups too small for an HR hire, at ₩1.5M a month.

Service business · Seoul, South Korea · Professional services