Where Do You Actually Find Threat Intelligence on the Dark Web?
If you've ever tried to build a threat intelligence pipeline, you know the hardest part isn't the analysis—it's finding the sources. Ransomware gang sites move. Telegram channels appear and disappear. Forums require invitations you don't have. You end up maintaining a spreadsheet of links that goes stale in a week. deepdarkCTI is an attempt to solve that problem by collecting these sources in one place.
What It Does
deepdarkCTI is a curated collection of Cyber Threat Intelligence sources from the Deep and Dark Web. The project gathers links and references to places where threat activity happens—the kind of sources you'd want to monitor if you're doing CTI work.
The README lists the specific categories of sources the project aims to monitor: Telegram channels, groups and chats; Discord channels; ransomware gang sites; forums related to cyber criminal activities and data leaks; markets; exploits databases; Twitter accounts; and RaaS (Ransomware As A Service) sites. That's a practical spread of where actual threat actors operate and communicate.
Beyond just a link list, the project includes a methods file that describes various techniques for searching and analyzing these sources. So it's not just "here are some URLs"—there's guidance on how to actually work with them.
The project has an official website at deepdarkcti.com, and there's a Telegram group for contributors and people active in CTI to propose new sources and discuss research tactics. You can request access through the maintainer's Twitter, Telegram, or Bluesky accounts.
Why It's Cool
-
It addresses a real gap in CTI workflows. Most threat intelligence resources focus on feeds and IoCs—the outputs of analysis. deepdarkCTI focuses on the inputs: where do you actually go to find information about threat actors? That's a different and arguably harder problem.
-
The source categories are specific and practical. The README doesn't just say "dark web sources." It breaks things down into ransomware gang sites, RaaS sites, data leak forums, exploit databases. If you're building monitoring around ransomware, you know exactly which section to look at.
-
The methods file adds operational value. Anyone can paste a list of links into a GitHub repo. Including documentation on search and analysis techniques suggests the maintainers actually use these sources and want to share how.
-
There's a community component. The Telegram group isn't just for announcements—it's for discussing "tactics and techniques of research and analysis that are used daily." That's the kind of knowledge that usually stays locked in private Slack channels at security firms.
-
It's honest about what it is. The README includes a straightforward definition of CTI, the three types of threat intelligence (strategic, tactical, operational), and typical sources of intelligence. This isn't trying to be something it's not—it's a reference collection with context.
The project also accepts donations, which the README notes will be managed transparently and used exclusively for building resources related to deepdarkCTI. That's a reasonable ask for a project that requires ongoing maintenance as sources change.
How to Try It
-
Go to the repository: https://github.com/fastfire/deepdarkcti
-
Browse the source categories. The README lists what's covered, and the repo structure should organize these into accessible sections.
-
Check out the methods file for search and analysis techniques. This is where you'll find guidance on actually working with the sources.
-
If you want to contribute or discuss CTI tactics, request access to the Telegram group. You can reach out via:
- Twitter: https://twitter.com/fastfire
- Telegram: https://t.me/fastfire83
- Bluesky: https://bsky.app/profile/fastfire.bsky.social
-
If you find it useful and want to support the project, there's a Buy Me A Coffee link in the README.
There's no installation process here—it's a collection of resources, not a tool you run. You'll want to clone or bookmark the repo and check back periodically as sources are added.
Final Thoughts
deepdarkCTI is best suited for security researchers, threat analysts, and anyone building CTI capabilities who needs a starting point for source discovery. It won't do the analysis for you, and it won't replace a commercial threat intelligence platform. But as a curated, community-maintained index of where threat activity actually happens, it fills a gap that a lot of CTI documentation ignores. If you've been building your own list of dark web sources in a notes app, this is probably a better version of that. And if you have sources to contribute, the Telegram group gives you a way to give back.
Follow @githubprojects for more developer tools and open source projects.