🕶 Dark Web Intelligence (DARKINT)
Hidden Services and Closed Criminal Venues
Cyber & Threat
Sources
0
0 no-auth
Mission domains
0
reach
Data points
0
covered
Related INT
0
disciplines
🔍 Lookup
📊 Pre-built Queries · Dark Web Intelligence
📜 Playbook — Dark Web Intelligence collection
- Direction — frame the requirement for Dark Web Intelligence: what decision does this support, by when?
- Collection — collect from the 0 mapped sources (0 free) — filter the catalog by DARKINT; capture provenance and observe OPSEC.
- Processing — normalize, de-duplicate and enrich the collected data.
- Analysis — correlate against local holdings; apply ACH; assign confidence.
- Dissemination — open a case, draft a report, share via STIX/MISP.
- Feedback — set an alert rule / watchlist to monitor for change.
⚡ AI Skills & Automation
Automate unattended via the cron pipeline (collect → ingest → resolve → enrich → score → alert).
🧩 Advanced Capabilities
✨ Enrichment pathways
🎯 Mission
Dark Web Intelligence collects and analyzes activity from Tor and I2P hidden services, criminal markets, ransomware leak sites, and closed forums. It answers whether an organization's data is being sold or leaked, whether it is named as a ransomware victim, and what adversary personas and chatter reference the organization or its sector.
📡 Collection methods
- Crawling and indexing Tor/I2P hidden services and onion directories
- Monitoring ransomware data-leak sites for new victim disclosures and countdown timers
- Scraping criminal markets and forums for listings referencing the organization, brand, or credentials
- Tracking adversary personas across forums, escrow, and Telegram channels
- Extracting cryptocurrency addresses and contact handles from listings for downstream correlation
- Fingerprinting onion services (SSH keys, analytics IDs, mail servers) to deanonymize infrastructure
📚 Key sources & datasets
🎫 Data points produced
🔧 Tools & frameworks
- TorBot
- OnionScan
- Tor Browser
- Photon
- Katana
- Fresh Onions
- Maltego
- Telethon
📜 Dark Web Intelligence Tradecraft
- Crawl onion directories, leak sites, and monitored forums/channels against a watchlist of brand and sector keywords
- Extract and normalize listings, victim posts, handles, and crypto addresses, capturing screenshots and timestamps as evidence
- Analyze context to judge whether a mention is a genuine compromise, resale, or noise, and gauge data sensitivity
- Attribute posts to a persona or ransomware affiliate by correlating handles, PGP keys, wallet reuse, and writing style
- Disseminate early-warning briefs to incident response and legal with the source, freshness, and confidence of each finding
- Trigger IR engagement, law-enforcement referral, and monitoring for follow-on publication or price changes on the listing
📊 Dashboard KPIs
Leak sites monitoredNew victim postsBrand mentionsMarket listingsTracked personas
🔍 Pre-built queries
🔗 Cross-discipline pivots
🧩 Advanced Capabilities
Workstation · Copilot · AI Skills · Automation · Playbooks · Lookups · Docs · Reports
🤖 AI Copilot
⚡ AI Skills
🔍 Lookup & Enrich
📚 Docs & Reports
💡 Recommendations
- Explore related tools below
- Automate recurring work via cron