Data Points

🕶 Onion / Hidden Service

A Tor hidden service address on the dark web.
Cyber

Sources

0
0 no-auth

Disciplines

0
that use it

Mission domains

0
reach

Workbench

native tool

🔍 Lookup

📜 Playbook — Onion / Hidden Service exploitation

  1. Direction — frame the requirement for Onion / Hidden Service: what decision does this support, by when?
  2. Collection — pull the 0 mapped sources (0 free) and the native workbench (open); capture provenance and observe OPSEC.
  3. Processing — normalize, de-duplicate and enrich the collected data.
  4. Analysis — correlate against local holdings; apply ACH; assign confidence.
  5. Dissemination — open a case, draft a report, share via STIX/MISP.
  6. Feedback — set an alert rule / watchlist to monitor for change.

⚡ AI Skills & Automation

🤖 Copilot brief⚡ AI SkillsResolveEnrichAuto-CollectHuntReportExport

Automate unattended via the cron pipeline (collect → ingest → resolve → enrich → score → alert).

🎫 Onion / Hidden Service

An onion address is a Tor hidden-service identifier derived from the service's public key, hosting sites reachable only inside the Tor network. It matters because darknet markets, leak sites, and C2 panels operate here, and onion-to-clearnet operational mistakes are prime deanonymization pivots.

Format: v3 onion: 56-char base32 + '.onion' (ed25519 pubkey); legacy v2: 16-char base32 (deprecated); reachable only via Tor/SOCKS.

📡 How it is collected

  • Darknet crawling via Tor gateways
  • Ransomware leak-site monitoring
  • Onion indexes and pastes scraping
  • Threat-intel and forum sharing
  • Malware config extraction (onion C2)
  • Ahmia / search-engine harvesting

🧩 Analysis & hunting techniques

  • OnionScan operational-security fingerprinting
  • SSH/SSL key correlation to clearnet hosts
  • EXIF / favicon leakage analysis
  • Onion-to-clearnet Apache mod_status leaks
  • Bitcoin address & PGP-key linkage
  • Uptime / availability tracking
  • Mirror / clone detection
  • Content-similarity clustering across services

🔧 Tools

  • Tor Browser / torsocks
  • OnionScan
  • Ahmia crawler
  • torify + curl
  • OnionSearch
  • Fresh Onions
  • eyeballer / screenshotting

⚡ Workbench actions

  • Fetch via Tor proxy
  • Run OnionScan opsec audit
  • Correlate SSL/SSH keys to clearnet
  • Extract crypto & PGP artifacts
  • Track uptime & mirrors
  • Screenshot & content-hash
  • Pivot to leak dataset
  • Cluster related services

📊 Dashboard KPIs

Uptime / availability %Opsec leak countLinked crypto addressesMirror countClearnet correlation confidence
Workstation · Copilot · AI Skills · Automation · Playbooks · Lookups · Docs · Reports

🤖 AI Copilot

🔍 Lookup & Enrich

💡 Recommendations

⚙ Automation

Cron: 0 * * * * php /home/zaptf0zdggll/public_html/threats/cron.php