Dark Web Hunting Toolkit
Purpose-built investigative tools for law enforcement, forensic examiners, OSINT analysts, and cybersecurity professionals. Built by a practitioner, for practitioners.
Purpose-built investigative tools for law enforcement, forensic examiners, OSINT analysts, and cybersecurity professionals. Built by a practitioner, for practitioners.
Every tool in this collection is designed around one principle: produce court-ready, chain-of-custody-compliant output from the first run. No configuration. No post-processing. Evidence in, documented report out.
Every tool generates SHA-256 evidence manifests and structured session logs for full chain-of-custody integrity.
Reports are built to hold up: hashed artifacts, timestamps, and structured DOCX/PDF output ready for presentation.
Tools run as Python scripts on Windows, macOS, and Linux, with PyInstaller Windows executables for deployment without Python.
Several tools connect directly to a chapter in Dark Web Hunting, reinforcing concepts with working investigative software.
Built in Python. Documented for court. Free to use and modify under the terms of each tool's license.
Rebuilt from scratch as a fully structured, toolkit-compliant Tor crawler. Includes Tor port auto-detection, login/CAPTCHA handling, and a Windows executable build pipeline.
Builds standardized, court-defensible case folder structures from a template — evidence directories for Tor sites, I2P sites, screenshots, source code, HAR files, and more — so every investigation starts from a consistent, forensically sound layout.
Threat intelligence enrichment tool with modules for OTX/AlienVault, CISA KEV, and URLhaus, plus a setup wizard for API credential management. Enriches collected indicators against active threat intelligence feeds.
Tor hidden service search tool with Ahmia nonce retry handling, a configurable YAML search-engine builder, and ReportLab-generated PDF reporting for search sessions.
Extracts and investigates PGP keys and associated identity information gathered during dark web research, supporting attribution work.
Investigative tooling for I2P research and evidence collection, extending the toolkit's Tor-focused capabilities to the I2P network.
Release date pending
A comprehensive law enforcement training guide to investigating hidden networks, written for investigators, forensic examiners, prosecutors, and students preparing for dark web casework.
Todd G. Shipley is a certified fraud examiner and certified forensic computer examiner with decades of experience in law enforcement, digital forensics, and investigative training. He has trained investigators at agencies across the United States and internationally on digital evidence collection, dark web investigations, and cryptocurrency tracing.
The Dark Web Hunting Toolkit grew out of those training programs. Investigators needed practical, legally defensible tools that produced court-ready output without requiring deep technical expertise. Every tool in this collection was designed around that requirement.
Dark Intel, Inc provides training, consulting, and resources for law enforcement and forensic professionals working at the intersection of digital investigations and emerging technology.
View All Tools on GitHubReach out for training on the toolkit or to discuss a collaboration.
Contact Dark Intel