The best IntelX alternatives in 2026 are Revealer.US, DeHashed, Have I Been Pwned, Hudson Rock, Maltego, the Wayback Machine and archive.today pair, and Aleph from OCCRP. Each replaces a different part of what IntelX does, because IntelX is really three products stapled together: a leak and breach corpus, a historical web and document archive, and a darknet/selector search engine. Match the alternative to the job you actually run (identifier pivoting, exposure confirmation, archived-page recovery, or document corpus search). A single drop-in clone does not exist.
What Intelligence X actually does
Intelligence X (intelx.io) is a search engine built around selectors rather than keywords. You give it an email address, domain, URL, IP or CIDR, a Bitcoin address, an IPFS hash, or a MAC address, and it returns records from its own collections where that selector appears. That model is the whole point. Most search engines index pages; IntelX indexes identifiers inside documents.
Its collections span roughly four buckets:
- Leaks and breach dumps: combolists, database dumps, credential collections
- Darknet content: Tor and I2P material captured by their crawlers
- Historical archives: snapshots of pages and whole documents, kept even after the original goes away
- Public and paste sites: pastebin-style content, WHOIS history, public document sets
They also run phonebook.cz, which enumerates email addresses, subdomains and URLs for a domain. For a domain-scoped assessment that single free feature earns IntelX a bookmark regardless of what else you use.
Why practitioners go looking for alternatives
Four reasons come up constantly. Use them to shortlist, not as a vibe check.
1. Preview-versus-full-record friction. The free tier shows you that a record exists and gives you a truncated preview. Confirming what is actually in the record generally means a paid account. Fair as a business model; awkward as a first-pass triage tool when you have fifty selectors and only three matter.
2. No infostealer-log layer. A breach dump tells you a credential was exposed in a historical incident. An infostealer log tells you a specific machine was infected, when, and what was sitting in the browser vault at the time (session cookies, internal URLs, the lot). Different products, different urgency. IntelX is built primarily around the former.
3. It is corpus-first, not person-first. IntelX answers "where does this selector appear in my collections?" It does not attempt to resolve a person: no phone-to-name pivot, no address history, no account-existence sweep across live platforms. If your case is identify and profile a subject, corpus search is only one input.
4. Pricing and licensing fit. Access tiers, API quotas and permitted-use terms differ from other vendors, and enterprise procurement often has opinions. Check their current terms directly. We will not quote a competitor's price we cannot verify.
Revealer.US is not a consumer reporting agency, and its results may not be used to make employment, tenant, credit, or insurance eligibility decisions.
Quick comparison
| Tool | Replaces which IntelX job | Stealer-log data | Historical archive | API | Pricing model (as of writing) |
|---|---|---|---|---|---|
| Revealer.US | Selector search + person resolution | Yes | No (live + records focus) | Yes, documented | Free tier; paid from $12.99/mo; Enterprise custom |
| DeHashed | Leak corpus selector search | Partial | No | Yes | Subscription; check their site |
| Have I Been Pwned | Exposure confirmation | No | No | Yes (keyed) | Free search; low-cost API key |
| Hudson Rock | Infection intelligence | Yes (specialist) | No | Yes (commercial) | Free lookups + commercial tier |
| Maltego | Pivoting and link analysis | Via transforms | Via transforms | Transform/SDK | Community + commercial tiers |
| Wayback + archive.today | Historical page recovery | No | Yes (the strongest) | Wayback has one | Free |
| Aleph (OCCRP) | Document and entity corpus | No | Partial | Yes | Free, public interest |
Feature sets and prices change. Verify on each vendor's own site before committing budget. The only figures stated as fact here are ours.
1. Revealer.US: selector search that continues into person resolution
Disclosure: we build this one, so audit the claims rather than taking them on trust.
Revealer.US starts from the same premise as IntelX. You hold an identifier, not a name. It then carries the search further in two directions IntelX does not. First, one search by email, username, phone number, name, or address checks 800+ platforms, public records, and known breach datasets in a single pass, so account-existence sweeps and public-record resolution happen alongside the corpus hits. Second, AI Deep Search does recursive, agent-driven people intelligence: an identifier surfaced in one source is re-queried as a first-class selector against the rest, which is exactly the manual pivot loop analysts run by hand and lose an afternoon to.
Where it overlaps IntelX most directly is exposure data. Data breach lookup covers known breach datasets, and stealer logs covers infostealer output, the layer IntelX largely does not carry. For an email-first case, email lookup is the natural entry point; for handle-first work, username search.
Where it does not replace IntelX: there is no historical web archive and no darknet crawler corpus. If your workflow depends on retrieving a page or document that has since been removed from the clear web, keep IntelX or the archive tools below in the stack.
Fit: analysts whose cases end in "who is this and what is exposed", not "what documents mention this string". Free tier to start, paid self-serve plans from $12.99/mo, custom Enterprise, card and crypto accepted. See pricing and the API docs.
2. DeHashed: the closest like-for-like on leak corpus search
DeHashed is the most direct structural comparison to IntelX's leak side. You search by email, username, IP, name, phone, address, or hash, and it returns matching records from breach collections with the fields those records contained. Where IntelX gives you a document containing your selector, DeHashed gives you parsed rows.
The parsing is the product. A combolist retrieved as a raw file requires you to eyeball it; a normalised record set can be filtered, exported, and joined against other case data. For credential-exposure work specifically, structured beats raw.
Limits: it is a breach corpus and little else. No archived pages, no document search, no live account enumeration. Coverage of any single incident is a matter of what got parsed and ingested. As with every vendor in this category, absence of a result is not evidence of absence of exposure.
Fit: credential-focused investigations and incident response where you need fielded records, not files.
3. Have I Been Pwned: the free, authoritative confirmation layer
Have I Been Pwned does one thing and does it with more transparency than anyone: tell you which catalogued breaches an email address appears in. Every breach in the index has a documented description, date, and field list. That documentation is the product. It is what lets you write "the address appears in breach X, disclosed on date Y, which exposed these field types" in a report and have it survive review.
The API is keyed and cheap, domain-wide search is available to verified domain owners, and the Pwned Passwords range API lets you check password hashes without transmitting them.
Limits: it deliberately does not return passwords or record contents, and it does not cover combolists or stealer logs as a class. It confirms exposure; it does not detail it.
Fit: the free first check before you spend a paid query anywhere else, and the citation you put in the report.
4. Hudson Rock: infection intelligence rather than breach history
Hudson Rock specialises in infostealer telemetry: which machines were infected, when, by what family, and which corporate and personal credentials were resident on them. They publish free lookup endpoints for domain and email checks and sell the detailed product commercially.
This is the gap that bites people who treat IntelX as a complete stack. A three-year-old breach dump is a hygiene problem. A stealer log from last month with live session cookies and a VPN portal URL is an active incident. Treating them as the same class of finding is a mistake analysts make constantly.
Limits: narrow by design. Nothing outside infection data.
Fit: attack-surface work, third-party risk reviews, and any case where the question is "is this access live right now".
5. Maltego: the pivot graph on top of everything else
Maltego is not a data source; it is the workspace that other data sources feed. Its transform marketplace includes an Intelligence X transform set, so one common answer to "IntelX alternative" is actually "keep IntelX, drive it from Maltego alongside six other sources".
Twenty entities and forty relationships do not fit in tabs. A graph makes clusters and shared infrastructure obvious in a way a result list never does.
Limits: steep licensing at the commercial tiers, and it inherits the quality of whatever transforms you attach. A graph built on weak sources is a confident-looking wrong answer.
Fit: multi-entity investigations, link analysis, and team casework that needs a shareable artefact.
6. Wayback Machine and archive.today: the archive job, done properly
IntelX's archive collection is genuinely useful, but for pure "what did this page say before it changed" work the Internet Archive Wayback Machine and archive.today are the primary sources and they are free.
Use them as a pair. Wayback has vastly deeper history and a usable API, including the CDX endpoint for enumerating every capture of a URL pattern. That is how you spot when a page appeared, changed, or vanished. archive.today captures JavaScript-heavy pages that Wayback often renders badly, and it captures on demand, which matters when you need a page preserved before it is edited.
curl "http://web.archive.org/cdx/search/cdx?url=example.com/*&output=json&limit=50"
Limits: neither indexes by selector. You need to know the URL or domain. They also honour removal requests, so absence is not proof a page never existed.
Fit: evidence preservation and change tracking. Snapshot anything you cite before it moves.
7. Aleph (OCCRP): document and entity search for the investigative side
Aleph is OCCRP's public document search platform: leaked datasets, corporate registries, court filings, sanctions lists and public records, cross-referenced into entities. It covers the "search inside documents for a name" job that people often reach for IntelX to do, with an investigative-journalism corpus behind it rather than a breach corpus.
Entity cross-referencing is the standout. Upload or select a list of names and Aleph will tell you which appear across its collections and how they connect.
Limits: the corpus is what it is. Great for corporate, legal, and sanctions-adjacent research; not a credential source, not a darknet crawler.
Fit: due diligence, corporate structure work, and journalism-style research where documents are the evidence.
Building a stack instead of picking a winner
No single tool replaces IntelX, because IntelX is not one tool. A sensible replacement stack for most identifier-driven casework looks like this:
- Free confirmation first. Have I Been Pwned on the email, phonebook.cz or a domain enumeration pass on the domain. Cost nothing, narrows everything.
- Identifier expansion: Revealer.US for the wide sweep across platforms, records, and breach and stealer data from one selector.
- Corpus depth: DeHashed for parsed credential records, Hudson Rock when infection timing matters.
- Archive. Wayback and archive.today for anything you intend to cite.
- Structure: Maltego or a notes graph once entity count passes what you can hold in your head.
Two habits separate a defensible investigation from a pile of screenshots. Record the source and timestamp of every result, because corpora shift under you and a hit today may be unreproducible next quarter. And never treat a null result as a negative finding. It means that vendor's collection did not contain it, which is a much weaker statement than "it does not exist".
Legal and ethical boundaries
Everything above is used lawfully by security teams, fraud investigators, journalists, and researchers working with data that is already public or already leaked. The lawful framing still comes with rules. Do not use exposed credentials to access accounts. Confirming exposure is research; using it is unauthorised access. Respect the licensing and permitted-use terms of each platform, particularly around redistribution of breach data. Handle any personal data you retrieve under whatever privacy regime applies to you, minimise what you keep, and delete it when the case closes.
For anything that touches an eligibility decision (hiring, tenancy, credit, insurance), none of these tools is the right instrument. Those decisions require a consumer reporting agency operating under the Fair Credit Reporting Act, with the notice, consent, dispute and adverse-action machinery that comes with it. Public-records and OSINT search is a different activity with a different legal footing, and conflating the two creates real liability. Revealer.US is not a consumer reporting agency; if you need an FCRA-compliant report, use a CRA. Data removal and access requests can go through contact.
Frequently asked questions
Is Intelligence X free? There is a free public search tier that shows previews of matching records, plus free tools like phonebook.cz. Full record access and API quotas sit behind paid accounts. Check intelx.io for current tiers, since we cannot verify pricing on your behalf.
What is the closest single alternative to IntelX? For the leak-corpus half, DeHashed is the closest like-for-like. For the identifier-to-person half, Revealer.US goes further by adding live platform coverage, public records, and infostealer-log data. Neither replaces the historical archive collection.
Does Revealer.US search the darknet? Revealer.US searches 800+ platforms, public records, and known breach datasets, including infostealer logs. It is not a Tor crawler. For darknet page indexing specifically, IntelX or a dedicated onion search engine remains the right tool.
Why do different tools return different results for the same email? Because each vendor holds a different corpus, parses records differently, and ingests incidents on different schedules. Running two or three sources is normal practice, not redundancy. Treat a single null result as inconclusive.
Can I use these tools to screen a job applicant or tenant? Not lawfully, no. Employment, tenant, credit, and insurance decisions in the US require an FCRA-compliant report from a consumer reporting agency. OSINT and public-records platforms, including Revealer.US, are not consumer reporting agencies and must not be used for those decisions.
Do any of these offer an API for automation? Most do. Have I Been Pwned, DeHashed, Hudson Rock, Aleph, the Wayback CDX endpoint, and Revealer.US all expose programmatic access. See our API documentation. Quotas and permitted-use terms vary considerably, so read each vendor's terms before wiring one into a pipeline.