Dark Web Intelligence (DARKINT): Intelligence Discipline Guide
The dark web is not a place, it is an access-control problem. Most of what matters happens in venues no crawler indexes and no lurker gets invited to.
The dark web is not a place, it is an access-control problem. Most of what matters happens in venues no crawler indexes and no lurker gets invited to.
What Dark Web Intelligence is as a discipline
Dark web intelligence is the lawful collection and analysis of material from anonymity networks and closed criminal venues: Tor and I2P hidden services, invitation-only forums, extortion leak sites, automated vendor shops and encrypted messaging channels used for trade. Collection combines automated capture of reachable onion services, structured monitoring of ransomware leak sites, and analyst observation of forums and channels. The output is assessed reporting on capability, targeting, pricing, access brokerage and imminent data disclosure, not a folder of screenshots of criminal chatter.
Maturity runs from keyword alerting on indexed onion content, through persistent structured collection of leak sites and market listings, to sustained analyst presence with source evaluation and genuine language competence. Sub-methods include marketplace analytics covering vendor reputation, listing volume and pricing trends; access-broker tracking establishing what is for sale and at what price; and leak-site monitoring as an early indicator of confirmed compromise. Passive observation is the default and interaction a controlled, authorised exception.
Why it matters
This discipline answers whether your access, data or brand is already being traded, and by whom. A leak-site listing is frequently the first confirmed evidence of an intrusion that internal telemetry missed entirely. Access-broker advertisements describe the exact entry vector being sold against your sector, often before it is used. Pricing and demand signals show which of your assets adversaries actually value. No other source gives visibility into the criminal supply chain upstream of an attack.
What analysts actually look for
These are the concrete, observable signals that carry weight in this area of work:
- Ransomware leak-site listings naming victim organisations, with countdown timers, sample files and claimed data volumes and types
- Initial-access broker advertisements describing sector, revenue band, country, access type and asking price without naming the victim
- Vendor listings offering organisation-specific data: databases, VPN credentials, mailbox access or authenticated session cookies
- Forum reputation, escrow history and vouch counts establishing whether a seller is genuinely capable or a serial scammer
- Service offerings for loaders, phishing kits, bulletproof hosting and cash-out, indicating capability availability and prevailing cost
- Recruitment posts seeking insiders, developers, negotiators or intrusion operators for named affiliate programmes
- Operational security failures such as reused handles, PGP key fingerprints, cryptocurrency addresses and distinctive writing style linking personas
- Discussion of specific vulnerabilities, showing which exploits are commoditised and likely to see mass use in the near term
Where the data comes from
Authoritative and openly available collection points. Always confirm licensing and terms before operational or commercial use:
- Ransomware leak-site aggregators — ransomware.live and Ransomwatch collect victim listings, timestamps and group claims without direct site interaction
- Tor Project — The legitimate access method and reference documentation for reaching and understanding hidden services
- Intelligence X — Indexed archives of onion pages, leaks and paste content with historical snapshots after originals disappear
- Licensed venue collection — Flashpoint, Intel 471 and Recorded Future supply analyst-collected forum and market reporting with source vetting
- Public Telegram channels — Openly joinable channels now carry much leak distribution, hacktivist claiming and vendor advertising
- Public blockchain explorers — Payment addresses published by extortion groups are traceable on chain and link incidents together
- Court filings and takedown notices — Indictments and seizure banners give validated ground truth on operators, aliases and infrastructure
- abuse.ch trackers — Infrastructure overlap between clearnet hosting and hidden-service operations, useful for corroborating claims
A working method
A repeatable sequence beats ad-hoc searching. This is a practical starting workflow:
- Set collection requirements — Define precisely what you need: your names, supplier names, brand terms and sector access listings. Undirected browsing is a liability, not a method.
- Build isolated infrastructure — Use dedicated, monitored, non-attributable systems with no corporate identity, approved by legal and security before first use.
- Automate structured collection — Continuously capture leak-site listings and market pages with hashes and timestamps so the record retains evidentiary integrity.
- Grade the source — Score each venue and persona for reliability and each claim for credibility. Criminal claims are marketing and inflation is routine.
- Corroborate before acting — Validate a claimed breach against your own telemetry and any published sample before triggering incident response or regulatory notification.
- Escalate lawfully — Route confirmed victim data and criminal activity to legal, regulators and law enforcement per policy. Do not negotiate, engage or purchase.
- Report the assessment — Deliver what the finding means for your risk posture, with confidence language, rather than raw excerpts of criminal forum posts.
How this connects across the intelligence taxonomy
Intelligence work does not respect neat boundaries. The mission domain you are working, the disciplines you practise, and the data points you pivot on are one connected system. These are the direct relationships for this entry — every link is also a tag, so you can follow any thread across the whole library.
Applied in these mission domains
Operates on these data points
- Onion / Hidden Service — A Tor hidden service address on the dark web.
- Cryptocurrency Address — Blockchain wallet address for receiving or sending crypto assets.
- Messaging Handle — An identity on a messaging platform (Telegram, Signal, Discord) used for coordination and sales.
- Username / Handle — Screen name or handle used across online platforms and services.
- IP Address — Internet Protocol address identifying a device or server on a network.
- Domain Name — Human-readable address that maps to IP infrastructure via DNS.
- Password / Credential — An exposed password or credential pair from leaks or dumps.
- Data Breach — A known data breach or leak incident with exposed records.
- File Hash — Cryptographic fingerprint of a file, used for malware identification.
- Event / Incident — A discrete real-world occurrence — protest, strike, breach, seizure — with time, place, and actors.
Related disciplines
- Attack Surface Intelligence — Your Own Exposed Attack Surface
- Breach Intelligence — Exposed Credentials and Compromised Data
- Certificate Intelligence — TLS Certificates and Certificate Transparency
- Cyber Intelligence — Adversary Activity in Networks and Systems
- Domain Intelligence — Domains, DNS, and Registration Intelligence
- Malware Intelligence — Understanding Malicious Code
Inside the platform: where Dark Web Intelligence lives
The Quantus platform is 204 pages behind a 147-item sidebar organised into six working groups: Command (24 items), Dashboards (15), Threat Theaters (14), Intelligence Domains (15), Investigate (34), and Administration (45). This entry is not a page in isolation — it is a thread running through several of them.
The modules that matter most here:
discipline.php?d=DARKINT— Discipline hubsource-catalog.php?disc=DARKINT— Source catalogue filtered to this disciplineioc-type.php?t=onion— Onion / Hidden Service profileblockchain.php— Cryptocurrency Address profileip-profile.php— IP Address profilesearch.php— Advanced search, filter and pivotcorrelate.php— Correlation graphcases.php— Case management
Each dashboard is local-first: it renders from the platform’s own database rather than depending on a live third-party call, so it still works when an upstream API is unreachable or rate-limited. Heavy aggregates are cached with a hard query time cap and degrade to the last good value instead of hanging the page.
Automation, playbooks and AI skills
Analysis that only happens when someone remembers to run it is not a capability. The platform ships a 30-step automation pipeline (cron.php) that collects, ingests, resolves, enriches, correlates and scores on a schedule — 25 seeders, 11 resolvers and 7 enrichment runners, all idempotent and cursor-based so a run can be interrupted and resumed without duplicating or losing work.
AI skills that apply
The 16 one-click operations in ai-skills.php are deterministic jobs, not free-text generation. The ones that matter here:
- Threat Hunt
- Auto-Collect Feeds
- Enrichment → Local
- Summarise (Copilot)
- Generate Report
Alerting closes the loop: rules in alerts.php fire on new indicators matching a saved query, so a first sighting in this area raises a notification rather than waiting to be noticed at the next review.
Feeds, data sources and the API
The collection layer runs a feed registry of free, machine-readable sources — bulk blocklists and trackers (Maltrail, IPsum, FireHOL, the full abuse.ch corpora, phishing databases, Emerging Threats, Spamhaus, DigitalSide, ThreatView), authoritative government feeds (CISA KEV, OFAC, UN and EU sanctions lists), and reference datasets (RIR allocations, ip-to-ASN and geolocation tables, MITRE ATT&CK, EPSS). collect.php pulls them server-side on a schedule; feeds.php and source-catalog.php show what is registered, what it covers and when it last ran.
Anything the platform holds is reachable programmatically. The REST API in api.php exposes 11 endpoints — status, stats, search, lookup, recent, export, bulk_check, top_threats, by_category, categories, check — and export.php streams 18 formats in bounded chunks, so a million-row export neither exhausts memory nor times out:
STIX 2.1, MISP, OpenIOC 1.1, CEF (ArcSight), LEEF 2.0 (QRadar), Zeek/Bro intel, Snort/Suricata rules, Palo Alto EDL, BIND RPZ, hosts blackhole, iptables, CSV, JSON, NDJSON/JSONL, XML.
That covers the CTI standards (STIX 2.1, MISP, OpenIOC), SIEM ingestion (CEF, LEEF, Zeek), detection engines (Snort/Suricata), and direct enforcement (Palo Alto EDL, BIND RPZ, hosts, iptables) — so intelligence developed here can be actioned in the tools you already run, without a manual reformatting step. A TAXII 2.1 server and a MISP/RSS feed are also served for pull-based sharing.
Use cases
Three ways this entry earns its keep in day-to-day work:
- Triage under time pressure. An artifact or report lands and you need a defensible read in minutes, not days. Set collection requirements is the first move; the platform pre-computes the enrichment so the analyst spends the time on judgement rather than lookups.
- Building the picture. A single indicator is rarely the story. Automate structured collection turns one artifact into a network — shared infrastructure, repeated selectors, the same operator behind different names — via the correlation graph and the cross-entity link engine.
- Producing something actionable. Analysis that ends in a document nobody can use is wasted. Report the assessment feeds the case file, the detection rule, the block list or the referral — with sourcing attached so the recipient can verify it.
Case management (cases.php), watchlists, saved searches and scheduled reports mean the work persists between sessions and survives an analyst leaving the team.
How each sector uses Dark Web Intelligence
The same entry is worked very differently depending on who you are, what authority you hold, and what you are ultimately producing. A military analyst is supporting a commander’s decision; a journalist is meeting a publication standard; an NGO caseworker is protecting a person. The underlying artifacts are shared — the constraints, outputs and thresholds are not.
🎖 Military and defence
Defence practitioners observe anonymity network venues for indications and warning relevant to force protection and operational security: leaked personnel data, discussion of installations, sale of access to contractor networks, and extortion sites naming defence suppliers. Collection is observational and passive, from an isolated infrastructure with attribution management appropriate to the risk. The output feeds counterintelligence referrals, supplier risk assessments and operational security advisories, and occasionally supports indications and warning where criminal chatter precedes disruption of a supply chain. Constraint: purchase, engagement, negotiation and any form of undercover interaction are not available to a defence analyst, and require law enforcement or intelligence authorities that are held elsewhere.
🕵 National intelligence
National services run structured observation of closed venues under specific legal authority, with the crucial distinction that human-enabled access and undercover activity are authorised functions for them and not for anyone else. Requirements typically concern proliferation, sanctions circumvention, state-criminal relationships and access brokerage affecting national infrastructure. The analytic value is in the pattern rather than the post: who vouches for whom, what capabilities are being sold, and where criminal and state activity intersect. Handling is stringent because the venue, the access and the persona are all sensitive, so products are written to convey the finding without revealing how it was obtained or which venue it came from.
👮 Law enforcement
Investigators use dark web intelligence to identify offenders, victims and infrastructure. Passive observation of publicly reachable services requires no special authority in most jurisdictions, but covert engagement, persona creation and any test purchase require specific authorisation under the relevant undercover or covert human intelligence source regime, with proportionality and necessity documented. Evidence capture must be forensically sound: full page capture with hashes, timestamps, the onion address recorded exactly, and the capture tooling documented, because sites are ephemeral and often disappear before charge. Attribution runs through infrastructure seizure, financial tracing and operational security errors, and increasingly through international cooperation on takedowns.
🔍 Private investigation and corporate security
Corporate practitioners monitor extortion leak sites, access broker listings and credential markets for exposure of their own organisation, their executives and their suppliers. The lawful method is observation only. A private actor must not purchase data, must not engage with a threat actor persona, must not negotiate outside a specialist legal process, and must not download stolen datasets, since possession may itself be an offence and creates regulatory exposure over other peoples personal data. Findings drive incident response, notification decisions and supplier engagement. Where a listing indicates an active compromise, the correct response is internal investigation and law enforcement referral, not contact with the seller.
📰 Journalism and OSINT media
Journalists use these venues to report on criminal markets, extortion operations and the trade in surveillance capability. Verification requires capture with timestamps and independent corroboration, since claims made by criminal sellers are frequently false and leak sites list victims that were never breached. Do not pay for material, do not publish data that identifies victims, and do not republish links that direct readers to live criminal services. Protect researchers and sources who supplied access. Where a leak site names a victim, seek comment and consider the harm of confirming a breach before the organisation has notified affected people, particularly where the data concerns patients or children.
🌍 NGO, humanitarian and human rights
Human rights and anti-trafficking organisations monitor these venues to document exploitation, identify victims and evidence markets in surveillance tooling. Practice must be strictly victim-centred: the objective is safeguarding and accountability, never collection of exploitative material, and any encounter with child sexual abuse material triggers an immediate legally mandated referral and cessation of collection. Do no harm requires that documentation is not published in a way that identifies victims or drives them further underground. Duty of care to staff is exceptional here because of exposure to traumatic material, requiring rotation limits, supervision, clinical support and technical controls that reduce unnecessary exposure.
🎓 University and research
Researchers study these venues as a market and social system: pricing, reputation mechanisms, resilience after takedowns, and the structure of criminal service economies. Ethics approval is mandatory and non-trivial, since observation of forum users is human subjects research and infiltration is generally not approvable. Approved designs are almost always observation-only with data minimisation, no engagement, no purchase and no republication of identifying content. Legal review must cover possession offences, since collecting site content can capture unlawful material inadvertently. Publish methodology and aggregate findings rather than raw archives, and describe venues in a way that does not function as a directory.
Playbook: working Dark Web Intelligence end to end
A repeatable sequence, from the moment the requirement lands to the moment a product is delivered and the case is closed out. Each phase states what you are trying to establish, not merely what to click — the point is a defensible chain of reasoning, not a checklist.
Phase 1 — Establish legal authority and rules of engagement
Before any collection, define in writing what is permitted: observation only, no engagement, no purchase, no download of datasets, and mandatory stop and refer procedures for illegal material. Have counsel approve the rules, and confirm which activities require authorisation your organisation does not hold. Record the lawful basis for processing personal data encountered incidentally. A good output is a signed rules of engagement document with named approvers and an escalation route. Stop when every planned activity is matched to an authority and the prohibited list is explicit and understood by every analyst.
Phase 2 — Build isolated collection infrastructure
Stand up collection on infrastructure that is fully separated from corporate networks and identity: dedicated hardware or isolated virtual machines, no corporate credentials, no organisational network egress, and a documented rebuild process. Manage attribution appropriately, since the connection metadata and browser configuration are what expose an observer. Assume any content retrieved may be hostile and treat the environment as contaminated by default. A good output is a documented, rebuildable collection environment with a tested reset procedure. Stop when a compromise of the collection environment would not reach any corporate asset or identity.
Phase 3 — Define the collection requirement
Specify what you are looking for before browsing, because unstructured exploration of these venues is both unproductive and a duty of care problem. Typical requirements are organisational names and domains on extortion leak sites, credential and access listings matching your estate, mentions of executives, and supplier names. Convert each into concrete search terms and monitored locations. A good output is a requirement list with search terms, target venues and a named consumer for each. Stop when every planned collection activity traces to a requirement and speculative browsing has been removed from the workflow.
Phase 4 — Map the venue landscape
Identify which venues actually matter for your requirements rather than collecting everything reachable. That means the extortion leak sites relevant to your sector, the access broker and credential venues where your estate would appear, and the automated shops. Record for each venue its reachability, its posting conventions, its reliability history and its known law enforcement status, since seized sites continue to appear and mislead. A good output is a venue register with assessed relevance and reliability. Stop when the register covers the requirements and adding venues stops producing relevant material.
Phase 5 — Automate reachable capture
For services that are publicly reachable without credentials, automate capture on a schedule: full page content, images, posted file listings and metadata, with hashes and timestamps. Automation matters because leak site posts are frequently removed after payment and the window can be hours. Rate limit and handle failures gracefully, since these services are unstable by nature. A good output is a capture pipeline with a monitored success rate and an archive that preserves original content. Stop tuning when the pipeline reliably captures posts within the window that matters for your response process.
Phase 6 — Observe closed venues within authority
Where a venue requires registration or invitation, proceed only if your rules of engagement and legal authority permit it, which for most private organisations they do not. Passive reading of a venue you have lawful access to is different from creating a persona to obtain access, which is deception and generally requires law enforcement authorisation. Where access is not permitted, rely on licensed providers who hold the relevant authority, or on law enforcement partners. A good output is a documented decision on each venue. Stop at the boundary of your authority and record where the gap is.
Phase 7 — Verify claims before acting
Treat every claim as unverified. Leak sites list victims that were never breached, sellers advertise data they do not have, and old datasets are repackaged as new. Verify by examining sample content structure against what your systems would produce, by checking whether the claimed volume is plausible, by comparing against known prior breaches, and by internal investigation for corresponding evidence of intrusion. Do not download full datasets to verify. A good output is a verification assessment with a stated confidence. Stop when the claim is assessed as substantiated, unsubstantiated or unverifiable, and label it accordingly.
Phase 8 — Trigger internal response
Where a claim relating to your organisation is credible, trigger incident response immediately and in parallel with further collection, since the listing may be the first evidence of an intrusion that is still live. Provide responders with the exact claim, the timing, the actor and the associated malware family, and the actor known behaviour, which shapes the hunt. Involve legal and privacy early because notification clocks may already be running. A good output is a response engagement with the intelligence attached. Stop collecting for the response when the investigation has enough to scope internally.
Phase 9 — Protect analysts
Manage exposure deliberately. Set time limits on sessions involving traumatic material, rotate analysts, use technical controls that blur or suppress images by default, provide clinical supervision and make it routine rather than exceptional, and require immediate cessation and referral on any encounter with child sexual abuse material. Monitor for the operational security errors that fatigue produces, since a tired analyst is the main risk to an attributed collection environment. A good output is a welfare regime that is used rather than documented. Stop and reassess if analysts are avoiding reporting exposure.
Phase 10 — Preserve evidence properly
Capture in a form that survives challenge: full content rather than screenshots, the exact onion address, capture time in a stated timezone, tooling and version, and a hash of the stored artefact. Record the collection environment and the analyst. Where material may support prosecution, follow the evidential standard from the first capture, because these sites disappear and there is no second chance to collect properly. A good output is an evidence pack that another examiner could authenticate. Stop when every item that might be relied upon has continuity from capture to storage.
Phase 11 — Analyse patterns, not posts
The intelligence value is in the aggregate: which sectors an extortion group is prioritising this quarter, how quickly they publish after the deadline, which access brokers supply which ransomware operations, what a given capability costs and how that price is moving, and how a venue population reconstitutes after a takedown. Individual posts are inputs. Build time series and relationship data rather than a feed of screenshots. A good output is an assessed trend product answering a standing requirement. Stop when the analysis supports a decision rather than describing activity.
Phase 12 — Review lawfulness and value
Periodically review whether the collection is still lawful, still within the rules of engagement, and still producing decisions. Re-approve the rules when law or organisational posture changes, audit what analysts actually did against what was authorised, and retire venue coverage that has stopped producing. Check retention of collected material against the schedule, since archives of criminal venue content accumulate personal data and unlawful material risk. A good output is an audit record and a revised requirement set. Stop retaining anything without a documented purpose and deletion date.
The platform ships this as a step-checked workflow in playbooks.php, so progress is recorded against a case rather than held in someone’s head.
Source register: what to collect from, and how
Sources are listed with their access model so you can plan around cost and licensing before you build a dependency on them. Open means no account required; registration means a free account or API key; licensed means paid or institutional access. Always confirm current terms — licensing changes, and a source that was free for research may not be free for commercial or evidential use.
| Source | Access | What it gives you | How it is used here |
|---|---|---|---|
| Tor Project | Open | Documentation, software and design specifications for the anonymity network and its hidden service protocol. | Establishes how onion services work, which determines what can and cannot be observed or attributed. |
| Tor Metrics | Open | Published measurement data on network size, relay populations, bridge usage and hidden service statistics over time. | Provides the network-level baseline for assessing changes in service population and usage patterns. |
| Ahmia | Open | Search index of publicly reachable onion services that excludes abusive content categories by policy. | Discovery of reachable services relevant to a requirement without indiscriminate crawling of the network. |
| Ransomware.live | Open | Aggregated monitoring of ransomware extortion leak sites with victim listings, group attribution and posting timestamps. | Tracks which groups are naming which victims and when, supporting sector trend analysis and early warning. |
| abuse.ch projects | Open | Open datasets on malware families, command infrastructure and distribution, including ransomware loaders and botnets. | Links extortion branding observed on leak sites to the malware families and loaders behind the intrusions. |
| Malpedia | Registration | Curated malware family reference with naming synonyms and links to authoritative technical analysis. | Resolves the family and toolset associated with an extortion brand so responders know what to hunt for. |
| Europol | Open | European law enforcement agency publishing darknet market disruptions, operational results and organised crime assessments. | Establishes which venues have been seized, which changes how any content observed on them should be interpreted. |
| US Department of Justice | Open | Indictments and enforcement announcements including detailed narratives of marketplace operations and identification methods. | Provides evidenced ground truth about venue operations and about how operators were actually identified. |
| Internet Crime Complaint Center | Open | United States reporting channel and annual reporting on ransomware, extortion and cyber-enabled fraud losses. | Reporting route for organisations and a source of loss context for extortion trend assessment. |
| OFAC sanctions programmes | Open | Designations covering ransomware operators, mixing services and associated digital currency addresses. | Determines whether an extortion actor is designated, which makes any payment a legal question before an operational one. |
| UNODC | Open | United Nations office publishing research and standards on drug markets, trafficking and transnational organised crime. | Frames darknet market activity within the wider organised crime picture and supplies victim-centred practice standards. |
| Internet Watch Foundation | Open | United Kingdom charity operating the reporting and removal regime for child sexual abuse imagery online. | The mandated referral route when illegal material is encountered, and the source of handling obligations. |
| Have I Been Pwned | Open | Aggregated breach exposure index with verified breach descriptions and privacy-preserving lookup interfaces. | Checks whether a dataset advertised on a criminal venue corresponds to an already known and indexed breach. |
| MISP | Open | Open platform for structured storage and controlled sharing of intelligence including victim and extortion event objects. | Holds observations with provenance, handling markings and enforced retention on sensitive collected material. |
Prefer sources that publish a methodology and a revision history. A dataset that changes silently is a liability in any product that has to survive challenge.
Tooling
Tools commonly used against Dark Web Intelligence. None of these replace judgement, and each carries its own failure modes — know what a tool infers versus what it observes.
- Isolated collection virtual machines — Provide a disposable, rebuildable environment separated from corporate identity and network. Limitation: discipline dependent, and one credential reuse defeats the whole arrangement.
- Tor Browser and onion routing clients — Provide access to hidden services with sensible default protections. Limitation: default configuration is not an attribution management strategy on its own.
- Scheduled site capture and archiving frameworks — Preserve leak site posts before they are removed after payment. Limitation: onion services are unstable, so capture success rates need active monitoring.
- Content hashing and evidence packaging tools — Establish integrity and timing of captured material for later evidential use. Limitation: worthless unless applied at capture rather than retrospectively.
- Image suppression and blur-by-default viewers — Reduce unnecessary analyst exposure to traumatic material during triage. Limitation: reduces analytic detail, so it must be combined with controlled review.
- Keyword and entity monitoring pipelines — Alert on organisational, executive and supplier names appearing in captured content. Limitation: name collisions and transliteration produce noise requiring analyst review.
- MISP or case management with retention enforcement — Stores observations with provenance, handling markings and deletion dates. Limitation: only effective where deletion is actually enforced and audited.
- Licensed commercial dark web monitoring services — Provide coverage of closed venues that a private organisation cannot lawfully access itself. Limitation: sourcing is opaque and claims cannot be independently verified.
AI skills and automation in detail
These are deterministic jobs with defined inputs and outputs, not open-ended prompting. Each is idempotent and cursor-based: interrupt one and it resumes where it stopped rather than duplicating work or losing progress.
- Threat Hunt — Runs saved hypotheses against the corpus and surfaces what matches, with the query preserved as a versioned artifact.
- Auto-Collect Feeds — Pulls the registered feed set server-side on a schedule, recording per-feed status so a silently dead feed is visible.
- Enrichment → Local — Materialises enrichment into the local store so dashboards render from your own database instead of a live third-party call.
- Summarise (Copilot) — Produces a narrative summary beside the underlying records. It explains; it never creates indicators or assigns attribution.
- Generate Report — Assembles a sourced product from the current case or query, with provenance attached to each element.
A note on the boundary: the only skill that involves a language model is Summarise (Copilot), and it writes prose about records that already exist. Nothing else on this list involves generation of any kind. No indicator, relationship or attribution in the platform originates from a model. See the full skill list.
Tradecraft notes
The distinctions that separate a competent analyst from a fast one:
- Observation only is not a limitation to work around, it is the discipline. Purchase, negotiation and persona-based engagement require authorities held by law enforcement, and a private organisation that improvises them commits offences and destroys any later prosecution.
- Everything posted is a claim by a criminal with an incentive to exaggerate. Leak sites list victims that were never breached and sellers advertise data they do not hold, so verification precedes response rather than following it.
- The value is in the aggregate, not the post. Which sectors a group is prioritising, how fast it publishes after a deadline, and which brokers feed which operations are decisions-grade intelligence; individual screenshots are not.
- Seized sites keep operating in appearance. Content observed on a venue under law enforcement control is not what it appears to be, so the venue register must track takedown status or your analysis will be quietly wrong.
- Never download an advertised dataset to verify it. Structure comparison, plausibility of volume, overlap with known breaches and internal investigation answer the question without making your organisation the custodian of stolen personal data.
- Analyst welfare is an operational control, not a wellbeing initiative. Fatigue and desensitisation cause the operational security errors that expose a collection environment, so rotation and supervision protect the capability as well as the person.
- Capture full content with hashes and exact addresses at the moment of observation. These services disappear without warning, screenshots are weak evidence, and there is rarely a second opportunity to collect the same material.
- Extortion listing timing is intelligence in itself. The interval between intrusion, negotiation failure and publication tells you where in the cycle a victim is, which is exactly what a responder needs to know.
Measuring whether it is working
Capability claims should be falsifiable. These are the measures that show whether work on Dark Web Intelligence is producing anything, and they are worth baselining before you change process or tooling.
- Median time from an organisational or supplier name appearing on a leak site to internal incident response being engaged with the intelligence attached.
- Proportion of monitored claims correctly assessed as substantiated or unsubstantiated, measured against the outcome of the subsequent investigation.
- Number of collection activities conducted outside the documented rules of engagement, which should be zero and is a governance failure rather than a performance measure.
- Share of captured evidence packs meeting the evidential standard for capture time, hashing and address recording without retrospective correction.
- Analyst exposure hours to traumatic material per period, with rotation compliance and supervision uptake tracked alongside.
- Proportion of issued products that are assessed trend analysis answering a standing requirement rather than reproduced screenshots.
- Retention compliance measured as the volume of collected material held past its scheduled deletion date, which should be zero.
Beware of measuring volume alone. Indicator counts and report counts rise easily and say little; time-to-attribution, proportion of findings that survive review, and how often a product changed a decision say a great deal.
Common pitfalls
- Taking criminal claims at face value, when victim lists routinely include recycled, exaggerated and entirely fabricated entries
- Undirected browsing that exposes analysts to illegal content, creating possession offences and welfare harm for no intelligence gain
- Interacting with sellers, which risks entrapment allegations, alerts the adversary, and can constitute inducement or facilitation
- Purchasing data or access to prove a breach, funding the criminal economy and creating handling liability for stolen property
- Attributing on handle reuse alone, when personas are shared, sold, inherited and impersonated across venues
- Collecting from corporate networks or identities, disclosing your interest and your organisation directly to the operators
Legal and ethical considerations
This is the most legally constrained discipline in the set. Accessing hidden services is lawful in most jurisdictions, but downloading stolen data, purchasing access or engaging vendors can amount to handling stolen goods, facilitation or unlawful processing of personal data. Interaction with criminal actors may compromise a future prosecution, and private organisations enjoy none of law enforcement protections. Operate under written policy with legal sign-off, minimise retention of third-party personal data, and record collection provenance with hashes so anything passed to authorities is evidentially sound.
Data integrity: no fabrication, no drift, no hallucination
Intelligence that cannot be traced back to a source is not intelligence, it is assertion. Everything in this entry — and everything in the platform behind it — is built on a small number of non-negotiable rules.
Provenance on every record
Every indicator carries the source that supplied it, a first-seen and last-seen timestamp, and a sighting count. Where several feeds report the same artifact, each contribution is recorded separately rather than collapsed, so you can see whether a finding rests on one source or twelve. Source attribution travels with the data into every export, so a recipient can audit a claim without asking you for the working.
Nothing is invented to fill a gap
If the platform has no data for Dark Web Intelligence, it says so. Empty is displayed as empty — never padded with plausible-looking placeholder values, sample records or illustrative examples that a reader might mistake for observations. A dashboard with no rows is a true statement about collection coverage, and it is treated as a gap to close, not a blemish to hide.
Scoring is deterministic and reproducible
Threat scores, reputation grades and risk tiers are computed from stated inputs with fixed weights, not estimated. The same inputs always produce the same output, and the formula is visible rather than a black box. Aggregates are cached with an explicit time-to-live so a figure on screen is never silently stale — and when a heavy query exceeds its time budget the platform serves the last known-good value and labels it, rather than inventing a fresh number or hanging.
Where AI is used, and where it is not
Language models summarise and explain. They do not create indicators, assign attribution or manufacture relationships. No IP address, wallet, hash or identity in the platform originates from a model — every one is ingested from a named feed, resolved from a reference dataset, or entered by an analyst with a source recorded. Copilot output is presented as narrative alongside the underlying records, never in place of them, so a reader can always check the summary against the evidence.
Guarding against drift
Enrichment is additive and timestamped rather than overwriting. Reference data — sanctions lists, allocations, taxonomies — is re-synchronised from the authority on a schedule instead of being edited in place, so local copies cannot quietly diverge from the source of truth. Attribution is recorded with a confidence level and the reporting it rests on, and inferred relationships are labelled as inferred. When a source retracts or corrects, the correction propagates rather than leaving a stale assertion behind.
What this means for you
You can put a finding from this platform in front of a regulator, a court, a board or a partner agency and show where each element came from. That is the standard the tooling is built to — because in this work, being confidently wrong is more damaging than being usefully uncertain.
By the numbers
The taxonomy this entry belongs to is not a marketing list — it is the actual structure of the platform: 52 mission domains, 52 intelligence disciplines and 65 data points, each with a live dashboard behind it. Supporting that: 18 indicator types, 14 playbooks, 16 AI skills, 18 export formats and a 30-step automated pipeline.
This particular entry connects directly to 10 data points, 6 mission domains, 6 closely related entries — every one of them a tag you can follow, and a dashboard you can open.
Questions analysts actually ask
Can we buy data on a criminal market to see if it is ours?
No. Purchase funds organised crime, may constitute handling stolen goods, facilitating unauthorised access or sanctions breach depending on the seller, and makes your organisation the custodian of other peoples stolen personal data with all the regulatory consequences. It also does not achieve the objective, since sellers routinely deliver nothing or deliver recycled material. Verification is done by comparing advertised structure and volume against what your systems would produce, by checking overlap with known breaches, and by investigating internally for corresponding intrusion evidence. Where the dataset genuinely matters, refer to law enforcement, who can obtain it lawfully.
Is it legal to browse a criminal forum?
Passive reading of a publicly reachable site is generally lawful in most jurisdictions, but several qualifications matter. Creating an account with false details may constitute deception; downloading certain content may constitute possession offences regardless of purpose, and this is absolute for child sexual abuse material where the only lawful response is immediate cessation and referral; and in some jurisdictions accessing certain venues carries specific restrictions. Get written legal advice for your jurisdiction and your sector, document the rules of engagement, and train analysts on the stop-and-refer procedure before anyone connects.
How reliable are extortion leak site listings?
Moderately, and less than they appear. Groups list victims to apply pressure and have clear incentives to overstate volume, exaggerate sensitivity and include organisations where the intrusion failed or touched only a supplier. Listings are also removed after payment, republished later, and sometimes duplicated across groups after affiliate disputes. Treat a listing as a strong prompt for internal investigation and a weak claim about the facts. The reliable elements are usually the timing and the group attribution; the claimed data volume and content should be independently established before any notification decision is made.
Should we negotiate with an extortion actor?
That is not an analyst function. Any engagement should run through specialist counsel and, where used, a professional response firm, with sanctions screening completed first because contact with a designated actor carries legal consequences before any payment is considered. The analyst contribution is to identify the group, its known behaviour on decryption and republication, its typical timelines and its affiliate structure, and to preserve the listing as evidence. Direct contact by internal staff routinely worsens the position, discloses information about the victim, and can breach insurance and regulatory obligations.
How do we protect analysts doing this work?
Treat exposure as an occupational hazard with controls. Limit session length and total exposure hours, rotate people off traumatic material rather than relying on volunteering, default to suppressed or blurred imagery in triage tooling, provide clinical supervision as routine practice rather than on request, and train the whole team on the mandatory referral procedure for illegal material. Managerially, watch for avoidance, cynicism and declining operational security discipline, which are the observable signs. The control is also operational: fatigued analysts make the mistakes that expose a collection environment.
Do we need our own collection or can we buy a service?
For most private organisations, a licensed service plus limited in-house monitoring of publicly reachable leak sites is the right balance. Closed venues generally cannot be accessed lawfully by a private organisation without deception, so paying a provider who holds the relevant authority and relationships is the compliant route to that material. What you should keep in-house is requirement setting, verification against your own estate, and the response integration, because those depend on internal knowledge. Interrogate any provider on their sourcing legality, since you inherit the risk of how they collected it.
What should we do when we encounter illegal material?
Stop immediately, do not save, copy, forward or examine further, and follow the mandatory referral procedure to the relevant national reporting body and to law enforcement. For child sexual abuse material this is absolute, applies regardless of investigative purpose, and is not subject to organisational discretion. Preserve only what the referral body instructs and record the encounter for the audit trail. Have this procedure written, trained and rehearsed before collection begins, because the decision cannot be made sensibly in the moment, and support the analyst involved afterwards as a matter of course.
Standards, frameworks and further reading
Work that references a recognised framework is easier to defend, easier to hand over, and easier for a partner to consume:
- The Budapest Convention on Cybercrime, which governs cross-border preservation, production and cooperation in investigations arising from these venues.
- The UK Regulation of Investigatory Powers Act 2000 and equivalent covert investigation regimes, which govern when persona-based engagement is lawful and by whom.
- ISO/IEC 27037 on digital evidence handling, which governs capture, integrity and continuity of material collected from ephemeral services.
- The Berkeley Protocol on Digital Open Source Investigations, which governs verification, preservation and analyst wellbeing in open source investigation.
- Traffic Light Protocol 2.0, which governs handling and onward sharing of sensitive observations between organisations.
- The UN Convention against Transnational Organized Crime, which governs cooperation on organised criminal groups operating across borders.
- OFAC and equivalent sanctions regulations, which govern the legality of any payment to a designated extortion actor or service.
- The EU General Data Protection Regulation and the UK Data Protection Act 2018, which govern retention and processing of personal data encountered during collection.
References
Primary sources and authoritative references for this entry. Publishers revise and retire material, so treat the retrieval date as part of the citation and re-check before relying on any of it in a formal product.
- Tor Project documentation — Tor Project. Design and operation of the anonymity network and onion services
- Tor network measurement data — Tor Metrics. Published statistics on network size, usage and hidden service populations
- Ransomware leak site monitoring — Ransomware.live. Aggregated victim listings and posting timestamps across extortion groups
- Darknet market disruption announcements — Europol. Operational record of venue seizures and takedowns affecting interpretation of collected content
- Cybercrime indictments and enforcement actions — US Department of Justice. Evidenced accounts of marketplace operations and operator identification
- Berkeley Protocol on Digital Open Source Investigations — UN Office of the High Commissioner for Human Rights. Methodological and ethical standard for open source investigation and analyst wellbeing
- Reporting and removal of illegal imagery — Internet Watch Foundation. Mandated reporting route and handling obligations for child sexual abuse material
- Sanctions programmes covering ransomware actors — US Office of Foreign Assets Control. Designations that determine the legality of extortion payments
- Transnational organised crime research — United Nations Office on Drugs and Crime. Research and standards framing darknet markets within organised crime
Link integrity: every reference above was verified with a live request when this page was generated. Where a publisher had moved or withdrawn a document, the link was repointed at a preserved copy in the Internet Archive and marked as archived. Anything with no reachable copy anywhere had its link removed rather than left to rot — the source is still credited, it simply cannot be linked.
Put it into practice
The Quantus Intel threat intelligence platform operationalises this entry: monitors leak sites and closed venues with source grading, provenance capture and corroboration workflow. Explore the platform, or browse the rest of the library by following any tag above.