πΆ Dark Web Intel theater
Surveils dark-web markets, forums, and leak sites trading stolen data, credentials, and initial access. Key to early warning of breaches and criminal supply chains.
Live indicators
80.4K
in this theater
High severity
0
score β₯ 0.75 (top 60)
Actors tracked
5
documented
Mapped sources
4
in catalog
🏹 Threat Actors
🦠 Malware & Tools
📚 Priority sources & datasets
🔄 Live Datasets & APIs (2 key-free Β· ingestible)
| Dataset / API | Format | Endpoint | |
|---|---|---|---|
| Ransomwatch Leak Sites | json | https://raw.githubusercontent.com/joshhighet/ransomwatch/mai | collect |
| Tor Bulk Exit List | text | https://check.torproject.org/torbulkexitlist | collect |
📜 Dark Web Intel Playbook
- Crawl marketplaces, forums, and leak sites over TOR for listings, credentials, and access sales.
- Parse and index harvested data, mapping vendor handles, PGP keys, and crypto addresses.
- Analyze stealer-log dumps and combolists for exposure of monitored assets.
- Attribute vendor personas by pivoting on reused handles, PGP fingerprints, and wallet clusters.
- Alert affected organizations to exposed credentials and initial-access broker listings.
- Enforce credential resets, monitor wallets, and support law-enforcement referral.
⚡ AI Skills & Automation
Automate unattended via the cron pipeline (collect → ingest → resolve → enrich → score → alert).
🎯 Add to case
🧩 Advanced Capabilities
🔗 Cross-domain pivots
Workstation Β· Copilot Β· AI Skills Β· Automation Β· Playbooks Β· Lookups Β· Docs Β· Reports
🤖 AI Copilot
⚡ AI Skills
🔍 Lookup & Enrich
📚 Docs & Reports
💡 Recommendations
- Explore related tools below
- Automate recurring work via cron