Skip to content
SecurityNew techTop 17% of today's analysed ideas

OSINT recon-as-a-service for pentesters

Build a hosted recon-as-a-service API or SaaS for pentesters and bug bounty hunters that aggregates OSINT lookups (email discovery, subdomain enum, identity chaining) with transparent source attribution and confidence scoring, then monetize via paid API credits or subscription the way MailAccess monetized its hosted tier. Target the active bug bounty and red team community that already pays for recon tooling like Hunter.io or SpiderFoot.

Original post

What to build

A hosted recon-as-a-service API/SaaS for pentesters and bug bounty hunters that aggregates email discovery, subdomain enumeration, and identity chaining lookups behind a single metered API, with per-result source attribution and a confidence score.

MailAccess's Show HN launch signals fresh interest in email OSINT tooling, and a hosted API that aggregates multiple recon techniques with attribution and confidence scoring could capture the bug bounty/red team spend that already flows to tools like Hunter.io and SpiderFoot.

Demand

Bug bounty hunters and red teamers run recon as a daily workflow and already pay for point-solution OSINT tools; a new email OSINT framework getting attention on HN right now shows the itch is active.

  • Hacker News (Show HN post)Engagement

    Show HN: MailAccess – the true Email OSINT framework — 66 points, 0 comments on HN; posted by a security engineer describing building the tool, high engagement at the source

  • Hunter.io / SpiderFoot (adjacent paid tools)Analysis

    Internal analysis cites Hunter.io and SpiderFoot as established paid recon tools, indicating the bug bounty/red team community already spends money on this category

Stack

  • FastAPI (Python) for the API layer
  • Hunter.io / Have I Been Pwned APIs for email data sources
  • Shodan API for subdomain/infra enrichment
  • Supabase (Postgres + auth + API key management)
  • Stripe metered billing
  • Redis/queue for async multi-source scans

Solo + AI difficulty

Wrapping a handful of existing OSINT APIs into a unified lookup endpoint and basic dashboard is straightforward with AI pair-coding (roughly 1-2 weeks to a thin MVP); the harder, slower parts are managing each upstream source's rate limits and ToS, building a believable confidence-scoring layer, and standing up abuse moderation, which push a sellable v1 closer to 4-6 weeks.

Entry threshold
Low capital and no licensing needed since it aggregates public OSINT sources, buildable solo with AI by scripting scrapers and a scoring layer over a weekend to a few weeks, but differentiation requires real methodology depth, not just another email-list scraper.
Window
12+ months

Where to find first users

  • Show HN launch post
  • r/bugbounty and r/netsec
  • Bug bounty platform communities (HackerOne/Bugcrowd Discords)
  • Infosec Twitter/X

Competitors

Counter-signals & risks

  • Email OSINT and recon tools carry significant dual-use risk; hosting such a service may attract misuse for stalking, harassment, or unauthorized reconnaissance, raising legal and abuse-moderation burdens.

  • The recon-as-a-service market already has entrenched, well-funded incumbents (Hunter.io, SpiderFoot, Recon-ng, theHarvester, Shodan), making differentiation and customer acquisition difficult.

  • Aggregating third-party OSINT sources into a paid API may violate those sources' terms of service or data protection regulations (e.g., GDPR) depending on data handled and region of operation.

Original title: Show HN: MailAccess – the true Email OSINT framework

  • Security#5

    Integrity monitoring for MCP server trust

    Build a lightweight monitoring tool that continuously hashes and diffs MCP server tool definitions and schemas against the version a user originally approved, alerting the moment a server silently changes behavior (a rug pull). Sell it as a CLI plus hosted dashboard to developer teams and security-conscious companies running multiple MCP servers in their AI agent stacks.

    Demand
    6/10
    est.
    Buildability
    9/10
    est.
    Competition
    7/10
    est.
    via Product Hunt
    22 competitors
  • Security#8

    Agent-access gatekeeper for the anti-bot web

    Build a middleware/compliance toolkit that helps website owners detect, rate-limit, and selectively allow AI agent traffic (shopping bots, booking agents) instead of blanket-blocking it — e.g. a drop-in reverse-proxy or CDN plugin that reads the emerging agent-identification standard, verifies agent identity/intent, and exposes an allowlist dashboard. A second, smaller product is a client-side diagnostic tool for agent builders that tells them why their agent got blocked on a given site and suggests workarounds within the new standard.

    Demand
    5/10
    est.
    Buildability
    6/10
    est.
    Competition
    6/10
    est.
    via TechCrunch
    33 competitors
  • Security#12

    AI agent tool for client-side authorization audits

    Build an AI-agent-driven security audit tool that automates detection of CWE-602 client-side-only authorization checks in mobile and web apps, the kind of flaw pentesters currently hunt for by hand. Package it as a scanning tool or CLI/API sold to bug bounty hunters, AppSec consultancies, and dev teams running pre-release security reviews.

    Demand
    8/10
    measured
    Buildability
    5/10
    est.
    Competition
    5/10
    est.
    via GitHub
    44 competitors
OSINT recon-as-a-service for pentesters — Nichr