Back to browse
I built a site that maps the web from a bounty hunter's perspective

I built a site that maps the web from a bounty hunter's perspective

by caffeinedoom·Mar 23, 2026·46 points·9 comments

AI Analysis

●●SolidDark HorseSolve My Problem

Pre-collected bug bounty recon data so you skip the scanning phase.

Strengths
  • No scans to run; data is already collected and ready for analysis
  • One-time $13.37 pricing instead of recurring subscription for exports
  • Tracks 1.8M+ URLs across 41 companies with HTTP status and tech stack
Weaknesses
  • Shodan, Censys, and SecurityTrails already offer similar recon data at scale
  • Only 41 companies tracked; limited coverage compared to established tools
Category
Target Audience

Bug bounty hunters and security researchers

Similar To

Shodan · SecurityTrails · Subfinder

Post Description

I built this because I wanted my own directory of public companies running bug bounty programs — where I could see their infrastructure in one place and have a real idea of where to start poking holes.

Neobotnet collects intel data from companies on HackerOne and Bugcrowd — subdomains, DNS records, web servers with status codes, indexed/crawled URLs, JS files, and exposed secrets/paths (still building this last part). The data is already there when you need it. No scans to run.

Currently tracking 41 companies, 63,878 web servers, and 1.8M+ URLs.

Long term I want to expand this to startups that depend on cloud infrastructure so they can see what's publicly accessible.

Made a free sample with Capital One's data (and other companies) so you can see what it looks like without signing up: https://freerecon.com

Original Page: https://neobotnet.com

Feedback very welcome.

Similar Projects

Security●●Solid

Lumina – passive OSINT recon tool for domains

Pulls together passive sources — crt.sh, Wayback, GitHub search, Shodan and Hunter — into a single HTML+JSON output so you can run recon without touching the target. It isn't reinventing OSINT, but the combination of multi-source subdomain enumeration, built-in WHOIS/JSON export and a ready-to-share dark report plus Docker support makes it an immediately useful tool for quick triage.

Niche GemShip It
surfruit
203mo ago
Security●●●Banger

Pentesting Tool Using Claude

Autonomous hunting with Burp MCP integration beats manual recon workflows.

Ship ItSolve My ProblemSlick
ishqdehlvi
312mo ago
Security●●Solid

WP-Hunter, WP recon and SAST tool (building Agentic AI pipeline)

Offline plugin catalog + Semgrep SAST combo saves researchers hours; WordPress ecosystem niche.

Solve My ProblemNiche Gem
xeloxa
103mo ago