nowfound

Life & fun · alternatives · 2026

24 alternatives to GrabbrApp

Research malicious infrastructure - securely and at scale

Below are 24 products that do a similar job, ranked by how close each is in meaning and then by launch-day votes. GrabbrApp launched in 2023; newer entries below may have overtaken it.

  1. 1

    See further and take the advantage back from the adversary

    2024 · its alternatives →

  2. 2AS

    Hey all, Last time when we were on HackerNews [1], we received a lot of feedback, and we incorporated most of it. - We have changed our name from grep.help to usegrasp.com - A privacy policy page - Bulk import - Pricing page We are happy to introduce a new feature: a personalized answer search engine that provides direct citations to the content on the page. Demo: https://usegrasp.com/search?q=is+starship+fully+reusable%3F 1 - https://news.ycombinator.com/item?id=35510949

    2023 · usegrasp.com · its alternatives →

  3. 3SS

    Excited to share the project I've been working on for the past 7 months! We've seen nearly weekly attacks against the open source software supply chain. I saw the seeds of this trend start in the mid 2015s as an open source maintainer and I've watched it only get worse over the years. I finally decided to try to solve this problem. Socket is taking an entirely new approach to one of the hardest problems in security in a stagnant part of the industry that has historically been obsessed with just reporting on known vulnerabilities. Unlike other scanning tools, Socket actually analyzes the…

    2022 · socket.dev · its alternatives →

  4. 4

    Cyber Breaches, Ransomware, Vulnerabilities & Research

    2024 · its alternatives →

  5. 5AT

    Hi everyone, I recently published a small open-source project. It’s a minimal network packet analyzer written in Go — designed more like a learning toy than a replacement for Wireshark. It currently supports parsing basic protocols like TLS, DNS, and HTTP, and includes a tiny fuzzing engine to test payload responses. You can inspect raw packet content directly from the terminal. The output is colored for readability, and the code structure is kept simple and clear. The entire program is very small — just about 400 lines of Go code. I know it’s not anywhere near Wireshark’s level, and I still…

    2025 · github.com · its alternatives →

  6. 6TH

    I wrote this tool during an internship at Narf Industries in 2023. It's a REPL that allows for quickly developing, testing, and fuzzing for HTTP request smuggling attack payloads. I started the internship having never worked with web servers, and have now found over 100 HTTP implementation bugs. I attribute this mostly to the ease of experimentation in the Garden. REPL-oriented fuzzing is just a really good interface for finding parsing bugs. It's pretty neat to able to run a differential fuzzer, categorize and display all the discovered discrepancies, then let a human pick through them and…

    2024 · github.com · its alternatives →

  7. 7MS

    I noticed the growing security concerns around MCP (https://news.ycombinator.com/item?id=43600192) and built an open source tool that can detect several patterns of tool poisoning attacks, exfiltration channels and cross-origin manipulations. MCP-Shield scans your installed servers (Cursor, Claude Desktop, etc.) and shows what each tool is trying to do at the instruction level, beyond just the API surface. It catches hidden instructions that try to read sensitive files, shadow other tools' behavior, or exfiltrate data. Example of what it detects: - Hidden instructions…

    2025 · github.com · its alternatives →

  8. 8
    HackGATE▲128

    Empowering ethical hacking with visibility and control

    2024 · its alternatives →

  9. 9

    Gain insights into blockchain hacks

    2024 · its alternatives →

  10. 10IS
  11. 11
    Trace-AI▲146

    Know What You Ship. Secure What You Depend On.

    Oct 2025 · trace-ai.dev · its alternatives →

  12. 12BO

    Hi HN, we’re the co-founders of Bearer, and today we launch an open-source alternative to code security solutions such as Snyk Code, SonarQube, or Checkmarx. Essentially, we help security & engineering teams to discover, filter and prioritize security risks and vulnerabilities in their codebase, with a unique approach through sensitive data (PII, PD, PHI). Our website is at https://www.bearer.com and our GitHub is here: https://github.com/bearer/bearer We are not originally Security experts but have been software developers and engineering leaders for over 15…

    2023 · its alternatives →

  13. 13DT
  14. 14BB

    This is a simple single-file python program that can find basic XSS (cross-site scripting) vulnerabilities in a target url. Most XSS discovery tools use a payload refelection strategy in which payloads are injected in url parameters and the GET response is inspected for places where the payload content is reflected. This is a very low precision XSS detection strategy because most reflection does not support execution. This program uses a different approach, and instead opens the target url in a browser, tests alert(...) payloads directly in the browser context, and listens for an alert being…

    2024 · github.com · its alternatives →

  15. 15

    Secure your JavaScript supply chain – block malware packages

    2022 · its alternatives →

  16. 16

    Take your security posture to the next level

    2023 · its alternatives →

  17. 17MS

    Hi HN! We kept seeing devs get pwned through MCP tools in ways that security scanners completely miss. So we built an open-source analyzer to catch these attacks. Our first OSS by Mighty team. The problem: At Defcon, we saw MCP exploits with 100% success rate against Claude and Llama. Three attack patterns: Hidden Unicode in "error messages" - Paste a colleague's error into Claude, your SSH keys get exfiltrated Trusted tool updates - That database tool you've used for months? Last week's update added credential theft Tool redefinition - Malicious tool redefines "deploy to prod" to run…

    2025 · github.com · its alternatives →

  18. 18
    Arnica▲97

    Behavior based software supply chain security

    2022 · its alternatives →

  19. 19

    Your digital assets exposed to the internet create threats.

    2021 · its alternatives →

  20. 20

    Free enterprise grade security for your personal browser

    2023 · its alternatives →

  21. 21OS

    Large Language Models (LLMs) are powerful, but they’re limited by fixed context windows and outdated knowledge. What if your AI could access live search, structured data extraction, OCR, and more—all through a standardized interface? We built the JigsawStack MCP Server, an open-source implementation of the Model Context Protocol (MCP) that lets any AI model call external tools effortlessly. Here’s what it unlocks: - Web Search & Scraping: Fetch live information and extract structured data from web pages. - OCR & Structured Data Extraction: Process images, receipts, invoices, and handwritten…

    2025 · its alternatives →

  22. 22ST
  23. 23TD

    Trusty - Search for an open source package to understand its trustworthiness based on activity, provenance, and more. Brought to you by the founders of projects such as Kubernetes and Sigstore. Hey, Luke here the CTO of stacklok. This is an early experimental preview of Trusty. We use statistical analysis to observe millions of packages and found that Malware typically follows certain patterns. We found this tool really useful to help understand the packages we our pulling into our software and wanted to share it with others. It's still early in and we have a lot more features that will be…

    2023 · trustypkg.dev · its alternatives →

  24. 24PT

    PryingDeep is a dark web OSINT tool. It specializes in extracting information depending on modules chosen. Here's an overview of the features: - Email, PhoneNumber, Wordpress search - PGP keys, Certificates and 3 different cryptocurrencies (XMR,BTC,ETH) search - PostgreSQL database, docker container for Tor and docker-compose for the whole project - A built in exporter, currently only JSON, but possibly more. - Exporter has support for: offset, limit, query building via the command line, raw-sql and different modules you can specify, e.g you only want emails, you will only get emails and the…

    2023 · github.com · its alternatives →

Also compare

Ranked by how close each launch is in meaning, then by votes. Prices were read from each product’s own site when checked and can change. Refine with your own description →