Our collection. Not someone else's.
Most dark web tools resell the same handful of upstream feeds. ThreatCluster runs its own collection stack across ransomware leak sites, underground forums, and Tor markets. We discover, enrich, and surface the content directly.
Three independent scrapers.
One scraper covers ransomware and data-leak group sites. The second covers underground forums. That includes paste sites, initial-access broker boards, combolists, and defacement archives. The third covers Tor and clearnet marketplaces.
Running them independently means a Tor outage on the marketplace side doesn't blind us to leak-site updates, and a forum being seized doesn't take down the ransomware tracking.
click to expand
We find our own sites.
Four sources find new sites in parallel. Curated CTI repositories, Tor search engines, GitHub-published onion lists, and Telegram channels.
New candidates go through liveness probing, a depth-1 link harvest, and automated classification. Most competitors buy a list. We build ours.
- Curated CTI repositories
- Tor search engines
- GitHub-published onion lists
- Telegram channels
click to expand
Every page, enriched twice.
We pull out the unambiguous indicators first. Crypto wallets, emails, Tox IDs, XMPP and Telegram handles, PGP blocks, CVE references. Anything with a predictable shape gets captured with a script, not a model.
AI then handles the contextual layer. Victim names, tools, attribution, language, and a one-paragraph summary. Everything cross-references into the main entity graph, so a victim domain or a tool name surfaces on its own entity page alongside the news.
click to expand
Surfaced the way an analyst reads it.
Group profile pages with active campaigns and historical victims. Per-victim detail pages with the enriched data attached. Markets with category tags. Underground forum posts with screenshots, captions, and metadata. Breach indexes filterable by country, sector, group, status, or freshness.
click to expand
Alerts when a client's domain hits a list.
Set the domains and supplier names you care about. When they appear in a ransomware victim post, a forum drop, a combolist, or a market listing, an alert fires through the same webhook and digest channels that the rest of the platform uses.
For MSSPs, alerts route per customer. Each client's mentions stay in their own channel, so the right team gets notified without one client ever seeing another client's hits.
click to expand
More of the platform
- Exposure ManagementAsset inventory ranked by CISA SSVC
- Threat HuntingIndustry threat models with SIEM-ready queries
- The Exploits DatabaseCVEs ranked by what defenders care about
- IOCs and ExportsSTIX, MISP, SIEM ingestion
- CLI and HeadlessREST API, tc command, agent tool
- For MSSPsPer-customer scoping across the platform
Dark web monitoring FAQ
What does dark web monitoring cover?
Ransomware and extortion leak sites, underground forums and markets. Victim postings, breach claims and actor activity are collected, enriched and clustered alongside the rest of the threat picture.
Do you buy a feed of leak-site data or collect it yourselves?
We collect it ourselves. Three independent scrapers run against the sites directly, so a single Tor outage or a bought-feed going dark does not blind our leak-site tracking.
Will I be told if one of my domains appears?
Yes. Track your own domains and your suppliers' as watched entities, and you are alerted when one is named on a leak site or in a breach claim.
Is the collection legal and ethical?
We collect only what is publicly posted on these sites for situational awareness, and personally identifying material in screenshots is redacted before anything is published. Nothing is purchased from or transacted with the actors.
How current is it?
Collection runs continuously. New victim postings and breach claims are picked up and clustered as they appear, often before the victim discloses publicly.
Watch the leak sites, not the news cycle.
Live coverage of the leak sites, forums, and markets that matter, with alerts when your clients show up. No reseller, no curation lag.