nowfound

Dev tools · alternatives · 2026

24 alternatives to ThreatPinch Lookup

Add OSINT & Threat tooltips to all pages. Use any REST API!

Below are 24 products that do a similar job, ranked by how close each is in meaning and then by launch-day votes. ThreatPinch Lookup launched in 2017; newer entries below may have overtaken it.

  1. 1

    Free enterprise grade security for your personal browser

    2023 · its alternatives →

  2. 2

    hey guys, wanted to show one of my side projects i just made public. the idea is basically another osint tool for pentesters and bug bounty hunters. it watches certificate transparency logs and checks newly-seen domains for exposed stuff like .env files, open .git dirs, config files, db dumps and so on, and puts whatever it finds into a searchable db. you just search a domain (or part of one) and see what's exposed. it's read-only and free. one thing i've been thinking about adding is a way to register for certain keywords and get notified when something new shows up for that search. would…

    Jul 2026 · search.cerast-intelligence.com · its alternatives →

  3. 3

    Chrome extension looks up phone/email/IP/people via APIs

    2021 · its alternatives →

  4. 4MS

    I noticed the growing security concerns around MCP (https://news.ycombinator.com/item?id=43600192) and built an open source tool that can detect several patterns of tool poisoning attacks, exfiltration channels and cross-origin manipulations. MCP-Shield scans your installed servers (Cursor, Claude Desktop, etc.) and shows what each tool is trying to do at the instruction level, beyond just the API surface. It catches hidden instructions that try to read sensitive files, shadow other tools' behavior, or exfiltrate data. Example of what it detects: - Hidden instructions…

    2025 · github.com · its alternatives →

  5. 5

    A security toolbox for developers

    2017 · its alternatives →

  6. 6

    Quickly scan your website and fix vulnerabilities

    2019 · its alternatives →

  7. 7BB

    This is a simple single-file python program that can find basic XSS (cross-site scripting) vulnerabilities in a target url. Most XSS discovery tools use a payload refelection strategy in which payloads are injected in url parameters and the GET response is inspected for places where the payload content is reflected. This is a very low precision XSS detection strategy because most reflection does not support execution. This program uses a different approach, and instead opens the target url in a browser, tests alert(...) payloads directly in the browser context, and listens for an alert being…

    2024 · github.com · its alternatives →

  8. 8

    A web tool to scan websites for common vulnerabilities

    2025 · webscan.dheerajjha.com · its alternatives →

  9. 9AS

    Hiya HN! Just released Artillery Probe - a Swiss army knife for testing HTTP from the CLI. Think mini-curl with better UX for common use-cases, plus a couple of extra features. Would love for you to try it and give some feedback! https://www.artillery.io/blog/swiss-army-knife-for-http-testing and: npm install artillery@latest What does it do? - First of all, it's a HTTP client! It does all the usual stuff you'd expect from a HTTP client... HTTP methods, request bodies, custom headers, forms, Basic Auth etc. - Got some JSON or XML back? It'll pretty-print it, and syntax…

    2022 · its alternatives →

  10. 10

    Python CLI tool for rapid IOC analysis (IPs, Domains, CVEs)

    Jul 2026 · github.com · its alternatives →

  11. 11

    The only OSINT tool you will ever need

    2023 · its alternatives →

  12. 12IR

    Sharing an internal tool that accelerated my development work 10-fold, especially with API debugging. Thought fellow developers here might find it useful. As a developer, I often have trouble reproducing errors at the client end. https://intercept.rest lets me debug and monitor API requests and responses. It is similar to the Network tab in Chrome Developer Tools but works for any API: mobile apps, webhooks, frontend etc. After I shared it with a close circle of friends, they found it incredibly useful and even found new use cases, I never imagined. Been a long time lurker here and…

    2018 · its alternatives →

  13. 13

    Research malicious infrastructure - securely and at scale

    2023 · its alternatives →

  14. 14

    See the potential security risk for every site you visit

    2022 · its alternatives →

  15. 15

    Bot, reputation and live probe of IP addresses for threats

    2023 · its alternatives →

  16. 16

    Anti-phishing extension that alerts you of dangerous sites

    2021 · its alternatives →

  17. 17

    Hey HN, I built an automated system that tracks malicious Chrome/Edge extensions daily. The database updates automatically by monitoring chrome-stats for removed extensions and scanning security blogs. Currently tracking 1000+ known malicious extensions with extension IDs, names, and dates. I'm working on detection tools (GUI + CLI) to scan locally installed extensions against this database, but wanted to share the raw data first since maintained threat intelligence lists like this are hard to find. The automation runs 24/7 and pushes updates to GitHub. Free to use for research,…

    Feb 2026 · github.com · its alternatives →

  18. 18
    Pingkat▲72

    Continuously monitor your website's public resources

    2023 · its alternatives →

  19. 19

    In-browser A.I. protection from online threats - all free

    Nov 2025 · its alternatives →

  20. 20RT
  21. 21AM

    I made an open source, MIT license Typescript library based on some of the latest research that generates prompt injection attacks. It is a super minimal/lightweight and designed to be super easy to use. Keen to hear your thoughts and please be responsible and only pen test systems where you have permission to pen test!

    2025 · prompt-injector.blueprintlab.io · its alternatives →

  22. 22
    TrAPI▲29

    API Security Simplified!

    2025 · linkedin.com · its alternatives →

  23. 23OS

    tl;dr we released openapi.security, an online tool that performs a dozen of security tests on any given openapi/swagger-based API, with no signup or email required. You can try it here: https://openapi.security My team at Escape (YC W23) is mainly focused on securing GraphQL APIs. For this, we developed a new approach called Feedback driven API Exploration. Basically, we infer the right security tests cases to run using the specification and a carefully crafted in house graph traversal algorithm. (It's a bit long to describe here but we published a more in depth explanation of…

    2023 · openapi.security · its alternatives →

  24. 24AS

Also compare

Ranked by how close each launch is in meaning, then by votes. Prices were read from each product’s own site when checked and can change. Refine with your own description →