monitoring-darkweb-sources

Featured

Monitors dark web forums, marketplaces, paste sites, and ransomware leak sites for mentions of organizational assets, leaked credentials, threatened attacks, and threat actor communications to provide early warning intelligence. Use when establishing dark web monitoring coverage, investigating specific data breach claims, or enriching incident investigations with dark web context. Activates for requests involving dark web OSINT, leak site monitoring, credential exposure, Recorded Future dark web, or Tor hidden service intelligence.

AI & Automation 12,642 stars 1468 forks Updated today Apache-2.0

Install

View on GitHub

Quality Score: 99/100

Stars 20%
100
Recency 20%
100
Frontmatter 20%
70
Documentation 15%
100
Issue Health 10%
50
License 10%
100
Description 5%
100

Skill Content

# Monitoring Dark Web Sources ## When to Use Use this skill when: - Establishing continuous monitoring for organizational domain names, executive names, and product brands on dark web forums - Investigating a reported data breach claim found on a ransomware leak site or paste site - Enriching an incident investigation with context about stolen credentials or planned attacks **Do not use** this skill without proper operational security measures — dark web browsing without isolation exposes analyst infrastructure to adversary counter-intelligence. ## Prerequisites - Commercial dark web monitoring service (Recorded Future, Flashpoint, Intel 471, or Cybersixgill) - Isolated operational environment: Whonix OS or Tails OS running in a VM with no persistent storage - Keyword watchlist: organization domain, key executive names, product names, IP ranges, known credentials - Legal guidance confirming passive monitoring is authorized in your jurisdiction ## Workflow ### Step 1: Establish Keyword Monitoring via Commercial Services Configure dark web monitoring keywords in your CTI platform (e.g., Recorded Future Exposure module): - Domain variations: `company.com`, `@company.com`, `company[dot]com` - Executive names: CEO, CISO, CFO full names - Product/brand names - Internal codenames or project names (if suspected breach scope is broad) - Known email domains for credential monitoring Most commercial services (Flashpoint, Intel 471, Cybersixgill) crawl forums like XSS, Exploit[....

Details

Author
mukul975
Repository
mukul975/Anthropic-Cybersecurity-Skills
Created
3 months ago
Last Updated
today
Language
Python
License
Apache-2.0

Similar Skills

Semantically similar based on skill content — not just same category

AI & Automation Featured

performing-dark-web-monitoring-for-threats

Dark web monitoring involves systematically scanning Tor hidden services, underground forums, paste sites, and dark web marketplaces to identify threats targeting an organization, including leaked cre

12,642 Updated today
mukul975
DevOps & Infrastructure Solid

brand-monitoring

When the user wants to monitor brand mentions, detect trademark infringement, or set up brand monitoring. Also use when the user mentions "brand monitoring," "brand watch," "trademark watch," "brand mentions," "impersonation detection," "counterfeit detection," or "brand abuse monitoring." For enforcement, use brand-protection.

553 Updated 3 weeks ago
kostja94
AI & Automation Featured

collecting-open-source-intelligence

Collects and synthesizes open-source intelligence (OSINT) about threat actors, malicious infrastructure, and attack campaigns using publicly available data sources, passive reconnaissance tools, and dark web monitoring. Use when investigating external threat actor infrastructure, performing pre-engagement reconnaissance for authorized red team assessments, or enriching CTI reports with publicly available adversary context. Activates for requests involving Maltego, Shodan, OSINT framework, SpiderFoot, or infrastructure reconnaissance.

12,642 Updated today
mukul975
AI & Automation Featured

analyzing-ransomware-leak-site-intelligence

Monitor and analyze ransomware group data leak sites (DLS) to track victim postings, extract threat intelligence on group tactics, and assess sector-specific ransomware risk for proactive defense.

12,642 Updated today
mukul975
AI & Automation Listed

analyzing-ransomware-leak-site-intelligence

Monitor and analyze ransomware group data leak sites (DLS) to track victim postings, extract threat intelligence on group tactics, and assess sector-specific ransomware risk for proactive defense.

4 Updated today
pinkpixel-dev