Comparisons
The free tools are excellent. Here is where Nightlatch fits.
Nightlatch does not try to replace KnockKnock, BlockBlock, LuLu, or Little Snitch. It covers a gap they leave: a continuous, multi-domain, local-only security-change diary — "what changed since yesterday" — with honest coverage gaps instead of false Quiet.
This is an early-warning change monitor. It does not replace antivirus, EDR, firewall, backups, or professional incident response.
| Capability | Nightlatch v0.1 | KnockKnock | BlockBlock | LuLu / Little Snitch |
|---|---|---|---|---|
| Continuous baseline drift | Yes — periodic + manual scan | On-demand scan | Persistence focus | Network rules / connections |
| Multi-domain story (persist + remote + listen + config) | Yes | Limited | Limited | No (network only) |
| Local-only, no account | Yes | Yes | Yes | Yes |
| Blocks / quarantines | No | No | Can block persistence | Firewall control |
| Resource-shape indicator (Porch Light) | v1.0 — shape only, no cause | No | No | No |
| Price model | $19 founding → $29 after 150 licenses | Free | Free | Free / ~$50–60 |
| Best when you want… | Readable "what changed" timeline across domains | Point-in-time persistence inventory | Real-time persistence blocking | Per-connection firewall decisions |
This table is intentionally generous to the incumbents.
When to pick Nightlatch — and when not to
Pick Nightlatch when…
- You run coding agents or automation and worry "what changed while I was not looking"
- You want one readable timeline, not four separate scanners
- You want zero telemetry and no vendor account by design
- You prefer "requires review" over "malware detected"
Pick the others when…
- You need to block a new persistence install immediately → BlockBlock
- You need to audit every outbound connection → Little Snitch / LuLu
- You need a deep one-off persistence inventory → KnockKnock
- You need enterprise fleet or EDR → Nightlatch is not EDR (see disclosure)
Nightlatch turns permission changes, persistence, remote doors, and network exposure into a local evidence story — without giving AI (or the app) control of your Mac.
What Nightlatch will not claim
No "antivirus," "EDR," "malware detected," "AI breakout," "guaranteed detection," or "blocks attacks" in v0.1 copy. Severity is limited to Info / Notice / Attention / CoverageGap. A gap is never shown as Quiet.
This is an early-warning change monitor. It does not replace antivirus, EDR, firewall, backups, or professional incident response.