Cyber Threat Intelligence Tools
Cyber Threat Intelligence (CTI) tools transform raw dark web data into actionable security intelligence. This guide covers ransomware tracking platforms, dark web monitoring services, OSINT browser tools, and directory services — with analysis of how each is used defensively and how threat actors leverage the same infrastructure.
Effective threat intelligence is the process of collecting, processing, and analyzing data about threat actors, their capabilities, infrastructure, and intentions — then using that intelligence to make informed security decisions. The dark web is one of the richest sources of threat intelligence available: criminal forums discuss vulnerabilities and attack techniques, ransomware leak sites reveal which organizations are being targeted, and breach repositories indicate which credential sets are actively being weaponized.
The tools described here represent the operational layer of dark web threat intelligence — the platforms security teams use to systematically monitor and respond to threats before they materialize as incidents. Understanding each tool's capabilities, data sources, and limitations is essential for building a proportionate and effective CTI program.
Use case scope: The tools and techniques described here support defensive security operations — monitoring for threats to your organization, understanding threat actor capabilities, and building effective defenses. Offensive use of CTI tools against systems you do not own or have authorization to access is illegal and outside the scope of this research guide.
Ransomware Tracker (Ransom.wiki)
Ransomware Tracker
Medium RiskRansomware Tracker (Ransom.wiki) aggregates victim data from ransomware group leak sites across the dark web, providing a searchable, normalized view of which organizations have been attacked by which ransomware groups. Monitoring ransomware trackers is the earliest possible warning that your organization — or a key supply chain vendor — has been compromised, often days before formal notification from the ransomware operator.
How It Works
Ransomware groups operate "leak sites" on the dark web — .onion addresses where they publish the names of victim organizations alongside threatened or completed data dumps. These sites serve as leverage: if the victim does not pay the ransom within the deadline, the group publishes the stolen data publicly. Ransomware Tracker crawls these leak sites continuously and aggregates all victim listings into a searchable database categorized by ransomware group, victim sector, and date.
Implementing Automated Monitoring
- Daily automated query of ransomware tracker APIs for your organization name, subsidiaries, and key vendors
- Appearance in any ransomware tracker = immediate P1 IR activation (notify CISO, legal, IR team within 15 minutes)
- Proactive sector monitoring: if 3+ industry peers are listed by the same group within 30 days, initiate threat hunting for that group's known IOCs
- Supply chain monitoring: treat any vendor listing as a potential compromise of shared credentials, API keys, or data
Key Insight: Timing Advantage
Mandiant M-Trends 2024 reports the median dwell time for ransomware operations is 5 days. Organizations that monitored ransomware trackers discovered breaches an average of 9 days earlier than those that did not — a critical difference in the window available to contain the incident before data is publicly released and reputational damage becomes irreversible.
DarkwebDaily
DarkwebDaily
Medium RiskDarkwebDaily is a dark web news aggregation platform providing daily briefings on emerging threats, new ransomware groups, vulnerability exploitation activity, and criminal market developments. It synthesizes intelligence from multiple dark web sources into a single clearnet-accessible feed, enabling security teams to maintain situational awareness without conducting individual dark web monitoring sessions.
Situational Awareness Integration
Integrate DarkwebDaily's RSS or API feed into your SIEM for automated keyword alerting. Configure alerts for: your organization name, industry sector terms (e.g., "healthcare," "financial services"), key vendor names, and currently unpatched CVEs in your environment. When a CVE actively exploited in the wild appears in DarkwebDaily reports, immediately cross-reference against your patch backlog — any reported vulnerability exploited in the wild that remains unpatched in your environment warrants P1 remediation escalation.
Threat Actor Intel Value
DarkwebDaily frequently surfaces intelligence about new threat actor groups and their TTPs before they appear in commercial threat intelligence feeds. Security teams that monitor this source can build MITRE ATT&CK-mapped threat profiles for emerging groups before those groups target their sector. MITRE ATT&CK PRE-ATT&CK TA0009 (Collection) identifies dark web news aggregation as a threat actor reconnaissance technique — defenders who monitor the same sources adversaries use understand what adversaries know about the threat landscape in their sector.
Mitaka
Mitaka
Low RiskMitaka is a browser extension for instant OSINT lookups that highlights IP addresses, domain names, file hashes, CVE identifiers, and other indicators of compromise (IOCs) on any web page and queries 90+ threat intelligence sources simultaneously. During dark web research sessions, Mitaka dramatically accelerates IOC enrichment — any indicator visible in TOR Browser can be instantly pivoted to VirusTotal, Shodan, URLscan, MISP, and dozens of other sources.
SOC Analyst Workflow Integration
- Highlight any IP address on a dark web forum post — Mitaka queries Shodan, GreyNoise, AbuseIPDB, and others simultaneously
- Domain names are cross-referenced against passive DNS, WHOIS, and malware analysis databases
- File hashes trigger VirusTotal, MalwareBazaar, and sandbox reports without leaving the browser
- CVE identifiers link to NVD, ExploitDB, and current exploitation activity reports
- Results aggregated in a side panel — no context switching required
Security Considerations
Install Mitaka only in an isolated research browser profile — the extension can read all pages visited. Your query patterns across 90+ intelligence sources may fingerprint your research subjects to third-party services. Review extension permissions carefully before installation. Rotate research profiles between investigations to prevent cross-contamination of query pattern fingerprints.
Enterprise Deployment
Deploy Mitaka on all SOC analyst workstations as a standard productivity tool for alert enrichment. Configure priority data sources based on your environment: organizations with significant cloud exposure should prioritize Shodan and Censys; organizations monitoring malware should prioritize MalwareBazaar and Any.run sandbox; financial sector teams should add fraud-specific threat intel sources. Standardizing the tool across the SOC ensures consistent enrichment quality regardless of which analyst handles an alert.
Onion.live
Onion.live
Medium RiskOnion.live is a clearnet site providing real-time status monitoring and mirror tracking for dark web services, including a dedicated ransomware section tracking active ransomware group leak sites. It serves as an uptime monitor and link aggregator for the dark web ecosystem, tracking when ransomware groups go offline, move to new .onion addresses, or publish new victims.
Ransomware Victim Early Warning
Onion.live's ransomware section provides near-real-time victim tracking across all major ransomware groups. Implement automated daily polling: monitor Onion.live's ransomware category for your organization name, all known subsidiaries, and key supply chain vendors. A positive match triggers P1 IR activation within 15 minutes — notify CISO, legal counsel, and IR team immediately. Begin evidence preservation before any communication with the threat actor. Assume all data listed as exfiltrated is already in threat actor hands regardless of whether it has been publicly published.
Infrastructure Change Tracking
When a ransomware group's leak site goes offline or moves to a new .onion address, Onion.live tracks the transition and provides updated mirror links. This enables defenders to maintain continuous monitoring even as threat actors shift infrastructure — critical for long-running investigations and supply chain risk assessments where a vendor might be listed days after the initial compromise.
Tor.link and Dark Web Directories
Tor.link & Dark Web Directories
Medium RiskTor.link is a comprehensive categorized directory of active .onion services including criminal markets, ransomware leak sites, fraud forums, and hacking services. For defenders, it serves as a structured map of the dark web ecosystem useful for maintaining blocklists and tracking the emergence of new criminal services.
Automated Blocklist Generation
Tor.link's categorized structure enables automated blocklist generation: weekly automation scrapes Tor.link categories (markets, ransomware, carding), extracts all listed .onion addresses, generates TOR2web proxy variants by appending known gateway suffixes (.onion.to, .onion.cab, .onion.pet, .onion.ly, .onion.ws), and pushes the complete list to the internal DNS blocklist. New listings in the ransomware or markets categories trigger a threat intelligence update to the SOC within 24 hours. Europol's Internet Organised Crime Threat Assessment (IOCTA) 2024 uses dark web directory data as a primary source for mapping the criminal marketplace ecosystem.
TOR2web and Gateway Blocking
TOR2web Gateways
High RiskTOR2web services act as transparent proxies between the clearnet and .onion dark web addresses, allowing any browser user to access .onion sites by appending a gateway suffix to the .onion address. This eliminates the need for a TOR client, dramatically lowering the technical barrier to dark web access and significantly expanding the population of potential unauthorized dark web users within corporate networks.
Gateway Domains to Block
The following TOR2web gateway suffixes should be blocked via DNS sinkhole and web proxy wildcard rules: .onion.to, .onion.cab, .onion.pet, .onion.ly, .onion.ws, .onion.lu, .onion.plus, .onion.rip, .onion.city. Implement Suricata/Snort rule detecting DNS queries containing ".onion." (with dots, catching all variants). Review weekly blocked-access logs — repeated TOR2web access attempts from a single host are a strong insider threat indicator. CISA Cybersecurity Advisory AA22-320A identifies TOR2web access as a significant data exfiltration vector used by ransomware affiliates to verify successful uploads to leak sites.
Building a Dark Web CTI Program
An effective dark web CTI program requires systematic coverage across three domains:
- Credential exposure monitoring: Daily breach database queries, HIBP Domain Search API, stealer log market monitoring. Alert on any corporate credential appearing in new breach data.
- Ransomware and leak site tracking: Automated polling of major ransomware trackers and Onion.live for organizational and vendor names. P1 alert on any match.
- Threat actor intelligence: DarkwebDaily feed integration, dark web forum monitoring for sector-specific threats, MITRE ATT&CK TTP mapping for active threat groups. Weekly briefing to security leadership.
Coverage gaps are filled by commercial dark web monitoring platforms that maintain their own infrastructure within the TOR network and provide enriched intelligence feeds. Evaluate commercial platforms (Recorded Future, Flashpoint, Cybersixgill) for programs requiring broader coverage than open-source tools provide.
