SlideShare a Scribd company logo
8
Most read
9
Most read
16
Most read
GETTING STARTED WITH
USING THE DARK WEB FOR
OSINT INVESTIGATIONS.
OLAKANMI OLUWOLE
20-03-2021
Our mission
To monitor and alert users of immediate risk using a tactical approach,
research, analyze and monitor the technical developments of various
cyber trends and threat-actors in the following fields:
How we are doing it
We gather massive amounts of data using various sources such as
publicly available web references, social media channels and the deep
dark web using a wide range of honey-pot techniques.
Cyber Threat Intelligence tailored for Africa
Getting started with using the Dark Web for OSINT investigations
Getting started with using the Dark Web for OSINT investigations
Global standards,
Local expertise.
OSINT
Opensource Intelligence. It’s the process of fetching and analyzing
publicly available data.
WHO USES OSINT?
Law enforcement, Cyber criminals, OSINT investigators, Private
investigators, Human Resource managers, etc.
We're investigating a missing person's case. The image missing.png
was the last image uploaded by the missing person. We're looking for the
location the person took and uploaded the picture and also the name of
Wi-Fi SSID the person posted from
CHALLENGE 01
https://docs.google.com/uc?export=download&id=1ob0uiTj45clIJIMcrDHVBkoMkfn5RQui
CLEARNET/SURFACE WEB
The Surface Web also called the Visible Web, Indexed Web, Indexable
Web or Lightnet, etc. is the portion of the internet that is readily available
to the general public and searchable with standard web search engines.
DEEP WEB
The deep web consist of a website or any page on the website which are
not indexed by search engines. It can only be access by authorized
personal Deep web is used to store most personal information like (Cloud
storages, any organization personal data and military data etc)
DARK WEB
The dark web forms a small part of the deep web, the part of the Web
not indexed by web search engines, although sometimes the term deep web is
mistakenly used to refer specifically to the dark web. Legal to access but any
illegal activity can be prosecuted.
TOR
Tor is free and open-source software for enabling anonymous communication
by directing Internet traffic through a free, worldwide, volunteer overlay network
consisting of more than seven thousand relays in order to conceal a user's
location and usage from anyone conducting network surveillance or traffic
analysis. To access the darknet, you need the Tor Browser.
REASONS TO USE THE DARKWEB
• Avoid internet censorship
• Anonymity
• Illegal Operations
• Investigations
JUST BEFORE YOU GET STARTED
• Tor network is automatically encrypted
• Domains on the dark web are randomly generated
• Transactions are mostly done using cryptocurrency, perfect money, etc.
• You can also access onion sites using Tor2web
• You won’t always find what you’re looking for
• A lot of sock puppets so real identification is tougher
RESOURCES TO GET STARTED - Clearnet
• https://onion.live/
• DeepDotWeb.com - Now seized by US DoJ
• Dark Search - https://darksearch.io/
• Hunchly daily dark web reports
• r/onion
RESOURCES TO GET STARTED – Dark Web
• Ahmia - http://msydqstlz2kzerdg.onion
• Dark Search - http://darkschn4iw2hxvpv2vy2uoxwkvs2padb56t3h4wqztre6upoc5qwgid.onion
• NotEvil - http://hss3uro2hsxfogfq.onion
• Quo - http://quosl6t6c64mnn7d.onion
• OnionLand - http://3bbad7fauom4d6sgppalyqddsqbf5u5p56b5k5uk2zxsy3d6ey2jobad.onion
• Tor66 Onions - http://tor66sewebgixwhcqfnp5inzp5x5uohhdy3kvtnyfxc2e5mxiuh34iid.onion/fresh
To Find Location:
- Look up wafflesncream '18 skateboard as seen on the image
- Results shows wafflesncream website
- Using any Exif tool, creating date of image is 2018
- Visit wafflencream website and search for 2018
- Results shows there was an event held at upbeat center and same picture is seen on the
website
To Find Wi-Fi SSID
- Now we know location is “Upbeat Center”
- Look up upbeat address
- Go to wigle.net and search for upbeat address area or long and lat
- Filter result to contain the year 2018
- Search for SSIDs in the area
- SSID "UpBeat" is seen with mac address seen in the image exif data
CHALLENGE
FLAG.
Tweet was seen regarding a breach but with little information. We need to
know where it was posted, user who posted, verify breach.
CHALLENGE 02
ADDITIONAL RESOURCES
• Server status – example.onion/server-status
• Censys.io - 443.https.tls.certificate.parsed.names: onion
• Shodan- ssl:“.onion”, “.onion”
• ExoneraTor - https://metrics.torproject.org/exonerator.html
• OnionScan - https://onionscan.org/
Getting started with using the Dark Web for OSINT investigations

More Related Content

What's hot (20)

PPTX
Digital Forensic ppt
Suchita Rawat
 
PDF
OSINT - Open Source Intelligence "Leading Intelligence and Investigation Tech...
Falgun Rathod
 
PPTX
How to Use Open Source Intelligence (OSINT) in Investigations
Case IQ
 
PPTX
Digital investigation
unnilala11
 
PDF
OSINT: Open Source Intelligence - Rohan Braganza
NSConclave
 
PDF
OSINT with Practical: Real Life Examples
SyedAmoz
 
PDF
Osint presentation nov 2019
Priyanka Aash
 
PDF
Open Source Intelligence (OSINT)
festival ICT 2016
 
PPTX
Cyber forensics ppt
RoshiniVijayakumar1
 
PPTX
Osint {open source intelligence }
AkshayJha40
 
PDF
Computer Security and Intrusion Detection(IDS/IPS)
LJ PROJECTS
 
PPTX
Digital forensics
yash sawarkar
 
PDF
PHDays 2018 Threat Hunting Hands-On Lab
Teymur Kheirkhabarov
 
PPTX
OpenSourceIntelligence-OSINT.pptx
anonymousanonymous428352
 
PPT
Open source intelligence
balakumaran779
 
PPTX
Introduction to Social engineering | Techniques of Social engineering
Prem Lamsal
 
PPTX
Ethical hacking presentation
Suryansh Srivastava
 
Digital Forensic ppt
Suchita Rawat
 
OSINT - Open Source Intelligence "Leading Intelligence and Investigation Tech...
Falgun Rathod
 
How to Use Open Source Intelligence (OSINT) in Investigations
Case IQ
 
Digital investigation
unnilala11
 
OSINT: Open Source Intelligence - Rohan Braganza
NSConclave
 
OSINT with Practical: Real Life Examples
SyedAmoz
 
Osint presentation nov 2019
Priyanka Aash
 
Open Source Intelligence (OSINT)
festival ICT 2016
 
Cyber forensics ppt
RoshiniVijayakumar1
 
Osint {open source intelligence }
AkshayJha40
 
Computer Security and Intrusion Detection(IDS/IPS)
LJ PROJECTS
 
Digital forensics
yash sawarkar
 
PHDays 2018 Threat Hunting Hands-On Lab
Teymur Kheirkhabarov
 
OpenSourceIntelligence-OSINT.pptx
anonymousanonymous428352
 
Open source intelligence
balakumaran779
 
Introduction to Social engineering | Techniques of Social engineering
Prem Lamsal
 
Ethical hacking presentation
Suryansh Srivastava
 

Similar to Getting started with using the Dark Web for OSINT investigations (20)

PPTX
ToR - Deep Web
Murray Security Services
 
PPTX
Research in the deep web
Seth Porter, MA, MLIS
 
PPTX
Case Study on Dark Web:Insights, Risks & Security Measures
BNAWAZALIHASHMI
 
ODP
The Deep and Dark Web
Swecha | స్వేచ్ఛ
 
PPTX
The Dark Web : Hidden Services
Anshu Singh
 
PPTX
Dark Web
KunalDas889957
 
PDF
Deep Dark Web - How to get inside?
Anshu Prateek
 
PPTX
Deep web, the unIndexed web
Nitish Joshi
 
PPTX
Journey To The Dark Web
MiteshWani
 
PDF
ABOUT DARK WEB
VenkatVs7
 
PPTX
Why We Need a Dark(er) Web
Jeroen Baert
 
PPTX
Acpe 2014 Internet Anonymity Using Tor
Jack Maynard
 
PPTX
Dark Web.pptx
eliofatjon
 
PPTX
Introduction To Dark Web
Adityakumar Yadav
 
PPTX
Dark Web and Privacy
Brian Pichman
 
PPTX
Dark web
Safwan Hashmi
 
PPT
Dark Net
jangezkhan
 
PPTX
Deep web
GauravPandey319
 
PPTX
darkwebbbvxvbjvccjjbvcgjnbvvvbnhc nmk.pptx
Geetha982072
 
PDF
Deeplight Intelliagg
Gavin O'Toole
 
ToR - Deep Web
Murray Security Services
 
Research in the deep web
Seth Porter, MA, MLIS
 
Case Study on Dark Web:Insights, Risks & Security Measures
BNAWAZALIHASHMI
 
The Deep and Dark Web
Swecha | స్వేచ్ఛ
 
The Dark Web : Hidden Services
Anshu Singh
 
Dark Web
KunalDas889957
 
Deep Dark Web - How to get inside?
Anshu Prateek
 
Deep web, the unIndexed web
Nitish Joshi
 
Journey To The Dark Web
MiteshWani
 
ABOUT DARK WEB
VenkatVs7
 
Why We Need a Dark(er) Web
Jeroen Baert
 
Acpe 2014 Internet Anonymity Using Tor
Jack Maynard
 
Dark Web.pptx
eliofatjon
 
Introduction To Dark Web
Adityakumar Yadav
 
Dark Web and Privacy
Brian Pichman
 
Dark web
Safwan Hashmi
 
Dark Net
jangezkhan
 
Deep web
GauravPandey319
 
darkwebbbvxvbjvccjjbvcgjnbvvvbnhc nmk.pptx
Geetha982072
 
Deeplight Intelliagg
Gavin O'Toole
 
Ad

Recently uploaded (20)

PDF
AI_MOD_1.pdf artificial intelligence notes
shreyarrce
 
PPTX
Orchestrating things in Angular application
Peter Abraham
 
PDF
𝐁𝐔𝐊𝐓𝐈 𝐊𝐄𝐌𝐄𝐍𝐀𝐍𝐆𝐀𝐍 𝐊𝐈𝐏𝐄𝐑𝟒𝐃 𝐇𝐀𝐑𝐈 𝐈𝐍𝐈 𝟐𝟎𝟐𝟓
hokimamad0
 
PPTX
internet básico presentacion es una red global
70965857
 
PPTX
Research Design - Report on seminar in thesis writing. PPTX
arvielobos1
 
PPTX
英国学位证(RCM毕业证书)皇家音乐学院毕业证书如何办理
Taqyea
 
PDF
How to Fix Error Code 16 in Adobe Photoshop A Step-by-Step Guide.pdf
Becky Lean
 
PDF
Apple_Environmental_Progress_Report_2025.pdf
yiukwong
 
PDF
Web Hosting for Shopify WooCommerce etc.
Harry_Phoneix Harry_Phoneix
 
PPT
Computer Securityyyyyyyy - Chapter 2.ppt
SolomonSB
 
PPTX
西班牙武康大学毕业证书{UCAMOfferUCAM成绩单水印}原版制作
Taqyea
 
PPTX
Optimization_Techniques_ML_Presentation.pptx
farispalayi
 
PPT
Agilent Optoelectronic Solutions for Mobile Application
andreashenniger2
 
PPT
introductio to computers by arthur janry
RamananMuthukrishnan
 
PPT
introduction to networking with basics coverage
RamananMuthukrishnan
 
PPTX
PE introd.pptxfrgfgfdgfdgfgrtretrt44t444
nepmithibai2024
 
PPTX
本科硕士学历佛罗里达大学毕业证(UF毕业证书)24小时在线办理
Taqyea
 
PPTX
Powerpoint Slides: Eco Economic Epochs.pptx
Steven McGee
 
PPTX
英国假毕业证诺森比亚大学成绩单GPA修改UNN学生卡网上可查学历成绩单
Taqyea
 
PPTX
PM200.pptxghjgfhjghjghjghjghjghjghjghjghjghj
breadpaan921
 
AI_MOD_1.pdf artificial intelligence notes
shreyarrce
 
Orchestrating things in Angular application
Peter Abraham
 
𝐁𝐔𝐊𝐓𝐈 𝐊𝐄𝐌𝐄𝐍𝐀𝐍𝐆𝐀𝐍 𝐊𝐈𝐏𝐄𝐑𝟒𝐃 𝐇𝐀𝐑𝐈 𝐈𝐍𝐈 𝟐𝟎𝟐𝟓
hokimamad0
 
internet básico presentacion es una red global
70965857
 
Research Design - Report on seminar in thesis writing. PPTX
arvielobos1
 
英国学位证(RCM毕业证书)皇家音乐学院毕业证书如何办理
Taqyea
 
How to Fix Error Code 16 in Adobe Photoshop A Step-by-Step Guide.pdf
Becky Lean
 
Apple_Environmental_Progress_Report_2025.pdf
yiukwong
 
Web Hosting for Shopify WooCommerce etc.
Harry_Phoneix Harry_Phoneix
 
Computer Securityyyyyyyy - Chapter 2.ppt
SolomonSB
 
西班牙武康大学毕业证书{UCAMOfferUCAM成绩单水印}原版制作
Taqyea
 
Optimization_Techniques_ML_Presentation.pptx
farispalayi
 
Agilent Optoelectronic Solutions for Mobile Application
andreashenniger2
 
introductio to computers by arthur janry
RamananMuthukrishnan
 
introduction to networking with basics coverage
RamananMuthukrishnan
 
PE introd.pptxfrgfgfdgfdgfgrtretrt44t444
nepmithibai2024
 
本科硕士学历佛罗里达大学毕业证(UF毕业证书)24小时在线办理
Taqyea
 
Powerpoint Slides: Eco Economic Epochs.pptx
Steven McGee
 
英国假毕业证诺森比亚大学成绩单GPA修改UNN学生卡网上可查学历成绩单
Taqyea
 
PM200.pptxghjgfhjghjghjghjghjghjghjghjghjghj
breadpaan921
 
Ad

Getting started with using the Dark Web for OSINT investigations

  • 1. GETTING STARTED WITH USING THE DARK WEB FOR OSINT INVESTIGATIONS. OLAKANMI OLUWOLE 20-03-2021
  • 2. Our mission To monitor and alert users of immediate risk using a tactical approach, research, analyze and monitor the technical developments of various cyber trends and threat-actors in the following fields:
  • 3. How we are doing it We gather massive amounts of data using various sources such as publicly available web references, social media channels and the deep dark web using a wide range of honey-pot techniques.
  • 4. Cyber Threat Intelligence tailored for Africa
  • 8. OSINT Opensource Intelligence. It’s the process of fetching and analyzing publicly available data. WHO USES OSINT? Law enforcement, Cyber criminals, OSINT investigators, Private investigators, Human Resource managers, etc.
  • 9. We're investigating a missing person's case. The image missing.png was the last image uploaded by the missing person. We're looking for the location the person took and uploaded the picture and also the name of Wi-Fi SSID the person posted from CHALLENGE 01 https://docs.google.com/uc?export=download&id=1ob0uiTj45clIJIMcrDHVBkoMkfn5RQui
  • 10. CLEARNET/SURFACE WEB The Surface Web also called the Visible Web, Indexed Web, Indexable Web or Lightnet, etc. is the portion of the internet that is readily available to the general public and searchable with standard web search engines. DEEP WEB The deep web consist of a website or any page on the website which are not indexed by search engines. It can only be access by authorized personal Deep web is used to store most personal information like (Cloud storages, any organization personal data and military data etc)
  • 11. DARK WEB The dark web forms a small part of the deep web, the part of the Web not indexed by web search engines, although sometimes the term deep web is mistakenly used to refer specifically to the dark web. Legal to access but any illegal activity can be prosecuted. TOR Tor is free and open-source software for enabling anonymous communication by directing Internet traffic through a free, worldwide, volunteer overlay network consisting of more than seven thousand relays in order to conceal a user's location and usage from anyone conducting network surveillance or traffic analysis. To access the darknet, you need the Tor Browser.
  • 12. REASONS TO USE THE DARKWEB • Avoid internet censorship • Anonymity • Illegal Operations • Investigations
  • 13. JUST BEFORE YOU GET STARTED • Tor network is automatically encrypted • Domains on the dark web are randomly generated • Transactions are mostly done using cryptocurrency, perfect money, etc. • You can also access onion sites using Tor2web • You won’t always find what you’re looking for • A lot of sock puppets so real identification is tougher
  • 14. RESOURCES TO GET STARTED - Clearnet • https://onion.live/ • DeepDotWeb.com - Now seized by US DoJ • Dark Search - https://darksearch.io/ • Hunchly daily dark web reports • r/onion
  • 15. RESOURCES TO GET STARTED – Dark Web • Ahmia - http://msydqstlz2kzerdg.onion • Dark Search - http://darkschn4iw2hxvpv2vy2uoxwkvs2padb56t3h4wqztre6upoc5qwgid.onion • NotEvil - http://hss3uro2hsxfogfq.onion • Quo - http://quosl6t6c64mnn7d.onion • OnionLand - http://3bbad7fauom4d6sgppalyqddsqbf5u5p56b5k5uk2zxsy3d6ey2jobad.onion • Tor66 Onions - http://tor66sewebgixwhcqfnp5inzp5x5uohhdy3kvtnyfxc2e5mxiuh34iid.onion/fresh
  • 16. To Find Location: - Look up wafflesncream '18 skateboard as seen on the image - Results shows wafflesncream website - Using any Exif tool, creating date of image is 2018 - Visit wafflencream website and search for 2018 - Results shows there was an event held at upbeat center and same picture is seen on the website To Find Wi-Fi SSID - Now we know location is “Upbeat Center” - Look up upbeat address - Go to wigle.net and search for upbeat address area or long and lat - Filter result to contain the year 2018 - Search for SSIDs in the area - SSID "UpBeat" is seen with mac address seen in the image exif data CHALLENGE FLAG.
  • 17. Tweet was seen regarding a breach but with little information. We need to know where it was posted, user who posted, verify breach. CHALLENGE 02
  • 18. ADDITIONAL RESOURCES • Server status – example.onion/server-status • Censys.io - 443.https.tls.certificate.parsed.names: onion • Shodan- ssl:“.onion”, “.onion” • ExoneraTor - https://metrics.torproject.org/exonerator.html • OnionScan - https://onionscan.org/