darkweb-intel

Identify onion services, marketplaces, and threat-actor pivots in Tor-enabled environments.

60|14|Updated Apr 27, 2026
One-click install
npx skills add https://github.com/brucesongs/kali-claw --skill darkweb-intel
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: darkweb-intel
Source: https://github.com/brucesongs/kali-claw/tree/main/skills/darkweb-intel
Command: npx skills add https://github.com/brucesongs/kali-claw --skill darkweb-intel

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Darkweb-intel provides a structured, OPSEC-conscious workflow to surface onion services, monitor marketplaces, and profile threat actors without exposing investigators.

Core Features & Use Cases

  • Tor-based access to onion services and discovery of target terms
  • Marketplace and breach data monitoring with actor pivot extraction
  • Threat actor profiling using PGP keys, wallets, and handle pivots
  • OPSEC-focused synthesis and encrypted evidence management for clients

Quick Start

Boot a Tor-enabled, isolated workspace and run the integrated dark web intel workflow to surface onion services, markets, and actor pivots while preserving OPSEC.

Frequently Asked Questions about darkweb-intel

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I discover and monitor onion services while maintaining OPSEC?

To discover onion services while maintaining OPSEC, you need a Tor-enabled, isolated workspace. This approach validates onion accessibility and monitors marketplaces while encrypting evidence to protect investigators from exposure.

What is the best way to profile threat actors using PGP keys and wallet pivots?

Threat actor profiling on the dark web leverages PGP keys, wallet pivots, and handle extraction from marketplace data. This process produces durable identifiers that link threat actors across multiple onion services and marketplaces.

Can I extract threat actor pivots from breach data on dark web marketplaces?

Yes, you can extract threat actor pivots from breach data on dark web marketplaces. The workflow monitors marketplace data and extracts actor pivots to build comprehensive threat profiles using PGP keys and wallet pivots.

Do I need a Tor-enabled isolated workspace to investigate onion services?

Before monitoring onion services, you must boot a Tor-enabled, isolated workspace to ensure strict OPSEC. This environment setup is required to safely validate onion accessibility and handle encrypted evidence.

How does encrypted evidence management work during dark web intelligence gathering?

Encrypted evidence management during dark web intelligence gathering secures collected marketplace data and actor profiles. It ensures that discovered onion services and threat actor pivots are preserved without exposing the investigator.

How does dark web intelligence gathering differ from general OSINT investigations?

Dark web intelligence gathering focuses on structured discovery and monitoring workflows, whereas general OSINT lacks Tor-specific OPSEC protocols. This approach validates onion accessibility and uses PGP keys and wallet pivots for durable threat profiling.