Deep and dark web intelligence

Table of contents
Deep and dark web intelligence

What is deep and dark web intelligence?

Deep and dark web intelligence is intelligence derived from non-indexed, access-controlled, and anonymized online environments, turned into findings an investigative or security team can act on.

A scraped listing from an onion-site marketplace is data. Knowing which actor operates that listing, which of their handles appear on two other forums, and which payment infrastructure they reuse is intelligence. This distinction matters because most of what circulates about "the dark web" is unverified — raw material that only becomes useful once an analyst tests it, corroborates it, and connects it to something else.

{{horizontal-line}}

What are the different layers of deep and dark web intelligence?

The discipline covers three distinct layers, plus one surface that often gets grouped in with them by mistake.

Layer What it is How you reach it Example
Surface web Pages indexed by search engines Any browser A public news article
Deep web Real pages that exist but are not indexed because they are gated, paywalled, database-driven, or behind a login A browser, plus credentials or the right query Court records systems, corporate registries, academic databases, private forums
Dark web Sites reachable only through an anonymizing network that conceals the location of both host and visitor Tor, I2P, or a similar overlay network An onion-service marketplace or a ransomware leak site
Encrypted messaging Not a web layer at all; closed channels and groups on messaging platforms The platform's own client, plus access to the channel Telegram or Discord channels advertising illicit services

{{57-deep-and-dark-web-intelligence-glossary-callout-1}}

Much of what gets described publicly as "dark web activity" now happens on encrypted messaging platforms that are not on the dark web at all. Treating them as one undifferentiated space leads teams to buy the wrong collection coverage. For example, a program built only for Tor crawling misses the channels where a growing share of recruitment, sales, and coordination actually takes place.

Dark web intelligence can include open-source intelligence (OSINT), but is not limited to it. Publicly accessible Tor content can reasonably fall within OSINT, but vetted forums, authenticated criminal communities, acquired datasets and persona-led access sit in different collection/tradecraft territory.

{{horizontal-line}}

How does deep and dark web intelligence work?

The process of gathering deep and dark web intelligence is typically not linear. Analysts move back and forth between several stages as a case develops.

1. Collection

Automated crawling of onion services and forums, monitored channel ingest, and analyst-led access to closed or vetted venues all feed collection, with much of the highest-value material sitting behind vetting, reputation, or paid membership. Every deep and dark web intelligence vendor has different access and collection vectors. The ideal state is one where investigators can access all of that information in one place.

2. Processing and enrichment

Processing pipelines de-duplicate raw collection, machine-translate it, and normalize slang and code words, then run it through entity extraction to pull out handles, wallet addresses, email addresses, PGP keys (the public key credentials vendors and forum members use to prove their identity and encrypt messages), phone numbers, and device identifiers. 

Every artifact carries provenance. For defensible intelligence, this should include the source/venue, collection time, original content or capture, relevant metadata, and ideally a stable reference or integrity mechanism.

3. Analysis and corroboration

Analysts pivot on handles, PGP keys, reused avatars, addresses, domains, IP addresses, URLs, email addresses, malware artifacts, certificates, cryptocurrency addresses, and infrastructure to find where else an actor has surfaced — then work to corroborate what they find across sources. It’s important to note that claims made on a forum are claims, not facts. Actors inflate their capabilities, misdirect competitors, and impersonate rivals, so a finding is only as strong as the corroboration behind it. 

{{57-deep-and-dark-web-intelligence-glossary-callout-2}}

4. Fusion with other intelligence

This is the step that separates an alert from an investigation. A handle can become attributable to a likely real-world identity when multiple independent sources converge. Deep and dark web selectors rarely resolve to an identity on their own; they resolve when an all-source investigation puts them next to everything else a team already knows.

{{horizontal-line}}

Why is deep and dark web intelligence important?

Certain precursor activity can be observable before impact, particularly initial-access brokerage, credential exposure, exploit/tooling sales, targeting discussion, and insider recruitment. Malicious actors advertise recruitment, tooling, access brokerage, victim data, and infrastructure in venues an investigator can reach, which makes this one of the few intelligence sources that is often predictive rather than purely forensic. Four payoffs follow:

  1. Early warning surfaces before use. Access sales, exploit brokerage, and insider recruitment can surface before operational use.
  2. Attribution often runs through persistent selectors. A handle, reused key, or piece of infrastructure shows up across otherwise unconnected cases and becomes the thread that ties them together.
  3. Victim identification and notification depend on breach and leak material, which frequently identifies who has been harmed before victims know it themselves.
  4. Disruption and recovery get faster, enabling takedowns, infrastructure blocking, credential resets, victim notification, account action, and (where financial intelligence supports it) tracing or freezing illicit proceeds.

{{horizontal-line}}

How are AI and agentic crime changing deep and dark web intelligence?

Generative AI and agentic tools have lowered the cost of running scaled, localized, native-sounding fraud. But investigators have gained ground too. 

Automated triage now covers volumes no analyst could read manually, cross-language normalization runs at collection speed rather than in a separate translation queue, and multi-hop pivoting — following a handle to a reused PGP key to a shipping record to an entity — can happen in a single query instead of a week of manual work.

{{57-deep-and-dark-web-intelligence-glossary-callout-3}}

{{horizontal-line}}

Who uses deep and dark web intelligence?

Audience Examples of what they use it for
Law enforcement and investigators Identifying a vendor or administrator, corroborating undercover reporting, and building the selector chain that supports a warrant application
National security analysts Tracking procurement networks, sanctions evasion facilitation, and adversary infrastructure advertised or brokered in closed venues — activity that rarely surfaces anywhere else
Cyber threat intelligence analysts Credential and infostealer exposure, ransomware/extortion activity, actor and campaign tracking, malware/tooling changes, vulnerability exploitation discussion, infrastructure discovery, targeting intent, and supply-chain exposure
Financial crime and fraud investigators Surfacing mule recruitment, laundering-as-a-service advertising, and stolen-card and account shops that only appear in these venues, along with the counterparty exposure they create
Corporate security and trust and safety teams Catching executive and brand impersonation, insider recruitment, and pre-attack reconnaissance aimed at their own organization before it turns into an incident
Regulators and policy teams Gathering evidence of how illicit services actually organize — the raw material that typology guidance and supervisory expectations rely on

{{horizontal-line}}

What sources feed deep and dark web intelligence?

Source What it yields Access reality
Onion-service marketplaces Vendor identities, product categories, escrow and cryptocurrency settlement infrastructure, reputation history Public-facing but volatile; sites disappear without warning
Closed and vetted forums Actor relationships, tooling, tradecraft discussion, dispute records Vetting, reputation, or paid membership required — the hardest and most valuable tier to reach
Ransomware and extortion leak sites Victim names, negotiation posture, timing, affiliate structure and recruitment, ransomware as a service (RaaS) advertisements, initial-access brokers, negotiation activity, tooling and infrastructure Public-facing and high-tempo, which requires continuous collection
Encrypted messaging channels Real-time advertising, recruitment, coordination Neither deep nor dark web; access is per-channel and often invite-gated
Breach dumps and credential markets (main credential exposure types include infostealer logs, combo lists, stealer-market listings, corporate-access/IAB listings, and breach datasets) Compromised accounts, identity data, insider access for sale, session cookies/tokens, device context Legal and handling constraints are significant; see the challenges below
Paste and file-sharing sites Short-lived dumps, configs, victim data Ephemeral; value depends on how quickly the material gets collected
Deep web records and registries Corporate ownership, licensing, litigation, shipping and trade records Legitimate and non-indexed, and frequently the source that turns a handle into a name

{{horizontal-line}}

What are the challenges of deep and dark web intelligence?

Challenge Why it slows investigations What addresses it
Access and vetting The highest-value venues gate entry by reputation, referral, or payment Sustained collection programs with persistent, documented access rather than one-off crawls
Ephemerality Sites, channels, and posts vanish; a source that cannot be re-collected cannot be re-verified Continuous collection with timestamped, preserved artifacts
Deception and inflation Actors exaggerate capability, impersonate rivals, and seed false claims Source reliability, information credibility, cross-source corroboration, and explicit confidence language on every finding
Language, slang, and code Material spans dozens of languages and fast-moving in-group vocabulary Machine translation paired with maintained lexicons and analyst review
Volume No team can read everything continuous collection produces Automated triage and entity extraction, with the audit trail preserved
Identity fragmentation One actor operates across many handles, venues, and platforms Selector-based entity resolution across sources
Legal authority and handling Collection, retention, and handling of breach and victim data carry constraints that vary by jurisdiction and by whether the team is public or private Documented authority, retention policy, and legal review — this is a legal question, not a tooling question
Analyst exposure Sustained exposure to this material carries a genuine welfare cost Rotation, support, and tooling that reduces unnecessary direct exposure

{{horizontal-line}}

Frequently asked questions (FAQs)

1. What is the difference between the deep web and the dark web?

The deep web is made up of real, indexable-quality pages that search engines simply don't crawl (e.g. paywalled content, private databases, gated registries). The dark web is a smaller set of sites reachable only through an anonymizing network like Tor, which conceals the location of both the host and the visitor.

2. Is deep and dark web intelligence the same as OSINT?

Deep and dark web intelligence can include open-source intelligence (OSINT), but is not limited to it. For example, public Tor content may be OSINT, but closed communities, vetted forums, and acquired breach material can require credentials, personas, access relationships, or commercial collection. 

3. How is dark web intelligence different from dark web monitoring?

Monitoring alerts an organization about its own exposure — leaked credentials, a mentioned brand name, a matched keyword. Intelligence goes further by answering who is behind an activity, how they operate, and what is likely to happen next; and it corroborates those answers against other sources instead of delivering a raw alert. Intelligence should also ultimately drive a decision or action. For cyber threat intelligence (CTI) specifically, that might mean a hunt hypothesis, detection change, credential reset, infrastructure block, vulnerability prioritization, supplier escalation, or takedown.

4. Is it legal to collect intelligence from the dark web?

Accessing public-facing onion services is generally lawful in most jurisdictions, in the same way that browsing any public website is lawful. Authority, retention, and handling requirements — especially for breach and victim data — vary by jurisdiction and by whether the collecting team is a private company or a government agency, so any specific collection program needs legal review against the laws that apply to it.

5. Can activity on the dark web be attributed to real people?

Frequently, yes — through persistent selectors, operational mistakes, and corroboration against non-anonymized records like corporate filings or shipping data. Attribution rarely rests on a single artifact; it comes from the same selector or pattern reappearing across multiple, independently verified sources.

6. Does dark web intelligence hold up as evidence?

Collected material can support a case when investigators document its provenance, integrity, and reproducibility from the moment of collection forward. Material collected without that documentation may still generate a useful lead, but it won't survive the same scrutiny.

7. Is Telegram part of the dark web?

No. Telegram, Discord, and similar platforms are encrypted messaging services, not dark web infrastructure — they don't run on Tor or a comparable anonymizing network, and reaching them doesn't require any special network access.

8. Who provides deep and dark web intelligence?

Providers generally fall into a few categories: dedicated dark web collection vendors, cyber threat intelligence platforms that layer analysis on top of collected data, and investigation platforms that fuse dark web findings with other categories of intelligence. What distinguishes them is collection quality and continuity, persistent access, historical depth, timeliness, provenance, source metadata, language/geographic coverage, entity resolution, and the ability to corroborate findings across independent sources. A provider with fewer but consistently accessed high-value communities can be substantially more useful than one advertising a larger raw source count.

Subscribe and stay up to date with our insights

Access our coverage of TRON, Solana and 23 other blockchains

Fill out the form to speak with our team about investigative professional services.

Services of interest
Select
Transaction Monitoring/Wallet Screening
Training Services
Training Services
 
By clicking the button below, you agree to the TRM Labs Privacy Policy.
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.

What is an onion service?

An onion service is a service hosted within Tor and addressed using a .onion address. This is an important technical detail behind the dark web's defining property: it conceals the location of both the site and the person visiting it. 

Most of what gets called "the dark web" (e.g. marketplaces, forums, leak sites) runs as onion services, and most of those marketplaces operate the same way darknet markets always have: as storefronts matching buyers and sellers of illicit goods and services, with reputation systems and escrow standing in for the trust a legitimate marketplace gets from regulation and brand.

Further reading

Speed only counts if the output stays sourced and auditable. Every AI-assisted finding needs to trace back to the specific collected artifact it came from, or it won’t survive a challenge.