Agent skill

Performing Dark Web Monitoring For Threats

by mukul975 in mukul975/Anthropic-Cybersecurity-Skills

Dark web monitoring involves systematically scanning Tor hidden services, underground forums, paste sites, and dark web marketplaces to identify threats targeting an organization, including leaked cre

Apache-2.0Auto-check passedDevOps & Cloud

Install Performing Dark Web Monitoring For Threats

skills CLI
$ npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill performing-dark-web-monitoring-for-threats -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install mukul975/Anthropic-Cybersecurity-Skills performing-dark-web-monitoring-for-threats --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/mukul975/Anthropic-Cybersecurity-Skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/performing-dark-web-monitoring-for-threats .claude/skills/performing-dark-web-monitoring-for-threats && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
performing-dark-web-monitoring-for-threats
GitHub stars
34k
Token cost
~2.5k tokens
SKILL.md length
425 words
Files
8 (incl. scripts, references, assets)
Skills in repo
644
Repo updated
First seen
Licence
Apache-2.0

At a glance

Dark web monitoring involves systematically scanning Tor hidden services, underground forums, paste sites, and dark web marketplaces to identify threats targeting an organization, including leaked cre

  • Works in 4 steps: Set Up Tor-Based HTTP Client → Monitor Paste Sites for Credential Leaks → Monitor Ransomware Leak Sites → …
  • DevOps & Cloud work in your project
  • SKILL.md covers Overview, When to Use, Prerequisites and Key Concepts, plus 3 more sections
  • Runs Python scripts from its folder; reaches haveibeenpwned.com and check.torproject.org

What it does

Performing Dark Web Monitoring For Threats is an agent skill from mukul975/Anthropic-Cybersecurity-Skills. Dark web monitoring involves systematically scanning Tor hidden services, underground forums, paste sites, and dark web marketplaces to identify threats targeting an organization, including leaked cre

Its SKILL.md is about 2.5k tokens, which your agent loads only when the skill is triggered. The skill folder holds 10 other files, including scripts, reference files and assets (for example `assets/template.md`, `references/api-reference.md` and `references/standards.md`).

It sits in DevOps & Cloud. The repository describes itself as: 817 structured cybersecurity skills for AI agents · Mapped to 6 frameworks: MITRE ATT&CK, NIST CSF 2.0, MITRE ATLAS, D3FEND, NIST AI RMF & MITRE F3 (Fight Fraud) · agentskills.io…. The licence is Apache-2.0.

When your agent uses it

  • DevOps & Cloud work in your project

Example prompts

  • “/performing-dark-web-monitoring-for-threats”

Requirements

  • Python 3
  • A credential in YOUR_HIBP_KEY

Workflow steps

4 steps, taken from the step headings in SKILL.md.

  1. Set Up Tor-Based HTTP Client
  2. Monitor Paste Sites for Credential Leaks
  3. Monitor Ransomware Leak Sites
  4. Generate Dark Web Intelligence Report

What it can do on your machine

Read from SKILL.md and the folder at commit 54a7988. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 2 files in scripts/ (Python), which the agent can run.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • haveibeenpwned.com
    • check.torproject.org
    • raw.githubusercontent.com

    Also links to:

    • torproject.org
    • github.com
    • darkowl.com
    • intel471.com
    • flare.io

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Performing Dark Web Monitoring For Threats loads about 2.5k tokens when it runs, and up to ~4.7k if it reads all its reference files. Until then it costs about 61 tokens; SKILL.md has 425 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~61
When it runs · the whole SKILL.md, loaded when a task matches
~2.5k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~4.7k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from mukul975/Anthropic-Cybersecurity-Skills at commit 54a7988, republished under its Apache-2.0 licence (© mukul975). 425 words, ~2,467 tokens.

Download SKILL.mdSave it as .claude/skills/performing-dark-web-monitoring-for-threats/SKILL.md (or your agent's skills folder). This skill also uses 7 other files; get the full folder from GitHub.
name
performing-dark-web-monitoring-for-threats
description
Dark web monitoring involves systematically scanning Tor hidden services, underground forums, paste sites, and dark web marketplaces to identify threats targeting an organization, including leaked cre
domain
cybersecurity
subdomain
threat-intelligence
tags
threat-intelligence, cti, ioc, mitre-attack, stix, dark-web, tor, threat-monitoring
version
1.0
author
mahipal
license
Apache-2.0
nist_csf
ID.RA-01, ID.RA-05, DE.CM-01, DE.AE-02
mitre_attack
T1591, T1592, T1593, T1589

Performing Dark Web Monitoring for Threats

Overview

Dark web monitoring involves systematically scanning Tor hidden services, underground forums, paste sites, and dark web marketplaces to identify threats targeting an organization, including leaked credentials, data breaches, threat actor discussions, vulnerability exploitation tools, and planned attacks. This skill covers setting up monitoring infrastructure, using Tor-based collection tools, implementing automated alerting for brand mentions and credential leaks, and analyzing dark web intelligence for actionable threat indicators.

When to Use

  • When conducting security assessments that involve performing dark web monitoring for threats
  • When following incident response procedures for related security events
  • When performing scheduled security testing or auditing activities
  • When validating security controls through hands-on testing

Prerequisites

  • Tor Browser and Tor proxy (SOCKS5 on port 9050)
  • Python 3.9+ with requests, stem, beautifulsoup4, stix2 libraries
  • Understanding of Tor hidden service architecture (.onion domains)
  • API access to dark web monitoring services (Flare, SpyCloud, DarkOwl, Intel 471)
  • Awareness of legal and ethical boundaries for dark web research
  • Isolated VM for dark web browsing (no personal or corporate identity leakage)

Key Concepts

Dark Web Intelligence Sources
  • Underground Forums: Hacking forums where threat actors discuss TTPs, sell exploits, and share tools
  • Paste Sites: Platforms for sharing stolen data, credentials, and code snippets
  • Marketplaces: Dark web markets selling stolen data, RaaS, exploit kits, and access
  • Telegram/Discord: Alternative communication channels for cybercriminal groups
  • Ransomware Leak Sites: Blogs where ransomware groups post stolen data from victims
Collection Methods
  • Automated Crawling: Tor-based web crawlers scanning hidden services
  • API-Based Monitoring: Commercial dark web monitoring APIs (Flare, DarkOwl, Intel 471)
  • Manual HUMINT: Analyst-driven research on specific forums and marketplaces
  • Credential Monitoring: Breach databases and paste site monitoring for leaked credentials
Show full SKILL.md (150 more words)Show less
OPSEC for Dark Web Research
  • Use dedicated VMs with no personal data
  • Route all traffic through Tor (Whonix or Tails recommended)
  • Never use personal accounts or identifiable information
  • Use separate email addresses and personas for forum registration
  • Disable JavaScript in Tor Browser for enhanced security
  • Never download or execute files from dark web sources on production systems

Workflow

Step 1: Set Up Tor-Based HTTP Client
python
import requests
from requests.adapters import HTTPAdapter

def create_tor_session():
    """Create a requests session routed through Tor SOCKS5 proxy."""
    session = requests.Session()
    session.proxies = {
        "http": "socks5h://127.0.0.1:9050",
        "https": "socks5h://127.0.0.1:9050",
    }
    session.headers.update({
        "User-Agent": "Mozilla/5.0 (Windows NT 10.0; rv:109.0) Gecko/20100101 Firefox/115.0",
    })
    return session


def verify_tor_connection(session):
    """Verify that traffic is routed through Tor."""
    try:
        resp = session.get("https://check.torproject.org/api/ip", timeout=30)
        data = resp.json()
        return {
            "is_tor": data.get("IsTor", False),
            "ip": data.get("IP", ""),
        }
    except Exception as e:
        return {"error": str(e)}
Step 2: Monitor Paste Sites for Credential Leaks
python
import re
from datetime import datetime

def monitor_paste_sites(session, organization_domains):
    """Monitor paste sites for leaked credentials matching organization domains."""
    findings = []

    # Check Have I Been Pwned API (clearnet)
    for domain in organization_domains:
        try:
            resp = requests.get(
                f"https://haveibeenpwned.com/api/v3/breaches",
                headers={"hibp-api-key": "YOUR_HIBP_KEY"},
                timeout=30,
            )
            if resp.status_code == 200:
                breaches = resp.json()
                for breach in breaches:
                    if domain.lower() in breach.get("Domain", "").lower():
                        findings.append({
                            "source": "HIBP",
                            "breach_name": breach["Name"],
                            "breach_date": breach.get("BreachDate"),
                            "data_classes": breach.get("DataClasses", []),
                            "pwn_count": breach.get("PwnCount", 0),
                            "domain": domain,
                        })
        except Exception as e:
            print(f"[-] HIBP error for {domain}: {e}")

    return findings


def search_for_keywords(session, keywords, onion_paste_urls):
    """Search dark web paste sites for specific keywords."""
    results = []

    for paste_url in onion_paste_urls:
        try:
            resp = session.get(paste_url, timeout=60)
            if resp.status_code == 200:
                content = resp.text.lower()
                for keyword in keywords:
                    if keyword.lower() in content:
                        results.append({
                            "url": paste_url,
                            "keyword": keyword,
                            "timestamp": datetime.utcnow().isoformat(),
                            "snippet": extract_context(content, keyword.lower()),
                        })
        except Exception as e:
            print(f"[-] Error fetching {paste_url}: {e}")

    return results


def extract_context(text, keyword, context_chars=200):
    """Extract text context around a keyword match."""
    idx = text.find(keyword)
    if idx == -1:
        return ""
    start = max(0, idx - context_chars)
    end = min(len(text), idx + len(keyword) + context_chars)
    return text[start:end]
Step 3: Monitor Ransomware Leak Sites
python
def check_ransomware_leak_sites(session, organization_name):
    """Check known ransomware group leak sites for organization mentions."""
    # Use Ransomwatch API (clearnet aggregator of ransomware leak sites)
    try:
        resp = requests.get(
            "https://raw.githubusercontent.com/joshhighet/ransomwatch/main/posts.json",
            timeout=30,
        )
        if resp.status_code == 200:
            posts = resp.json()
            matches = []
            for post in posts:
                post_title = post.get("post_title", "").lower()
                if organization_name.lower() in post_title:
                    matches.append({
                        "group": post.get("group_name", ""),
                        "title": post.get("post_title", ""),
                        "discovered": post.get("discovered", ""),
                        "url": post.get("post_url", ""),
                    })
            return matches
    except Exception as e:
        print(f"[-] Ransomwatch error: {e}")
    return []
Step 4: Generate Dark Web Intelligence Report
python
def generate_dark_web_report(findings, organization):
    """Generate structured dark web intelligence report."""
    report = {
        "organization": organization,
        "report_date": datetime.utcnow().isoformat(),
        "executive_summary": "",
        "credential_leaks": [],
        "ransomware_mentions": [],
        "dark_web_mentions": [],
        "recommendations": [],
    }

    for finding in findings:
        if finding.get("source") == "HIBP":
            report["credential_leaks"].append(finding)
        elif finding.get("group"):
            report["ransomware_mentions"].append(finding)
        else:
            report["dark_web_mentions"].append(finding)

    # Generate executive summary
    cred_count = len(report["credential_leaks"])
    ransom_count = len(report["ransomware_mentions"])
    report["executive_summary"] = (
        f"Monitoring identified {cred_count} credential leak sources "
        f"and {ransom_count} ransomware group mentions for {organization}."
    )

    if ransom_count > 0:
        report["recommendations"].append(
            "CRITICAL: Organization mentioned on ransomware leak site. "
            "Initiate incident response immediately."
        )
    if cred_count > 0:
        report["recommendations"].append(
            "HIGH: Leaked credentials detected. Force password resets for "
            "affected accounts and enable MFA."
        )

    return report

Validation Criteria

  • Tor connection established and verified via check.torproject.org
  • Credential leak monitoring returns results from HIBP and paste sites
  • Ransomware leak site monitoring identifies relevant mentions
  • Dark web intelligence report generated with actionable recommendations
  • All monitoring performed within legal and ethical boundaries
  • OPSEC maintained: no personal or corporate identity exposure

References

© mukul975, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 7 other files (scripts, references, assets) in skills/performing-dark-web-monitoring-for-threats of mukul975/Anthropic-Cybersecurity-Skills.

  • SKILL.md
  • LICENSE
  • assets/template.md
  • references/api-reference.md
  • references/standards.md
  • references/workflows.md
  • scripts/agent.py
  • scripts/process.py

Open the folder on GitHubat commit 54a7988

Compare with similar skills

Performing Dark Web Monitoring For Threats next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Performing Dark Web Monitoring For Threats compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Performing Dark Web Monitoring For Threats this skillmukul975/Anthropic-Cybersecurity-Skills34k—~2.5kAutomated safety check: PassApache-2.0
Iron Proxy Gateway for NanoClawnanocoai/nanoclaw31k—~4.6kAutomated safety check: NotesMIT
GitHub Actions Supply Chain Pinningasyncapi/generator1.1k—~1.9kAutomated safety check: PassApache-2.0
AWS Cloud Advisortech-leads-club/agent-skills7k—~2.1kAutomated safety check: PassCC-BY-4.0
KubeShark for KubernetesLukasNiessen/kubernetes-skill446—~1.2kAutomated safety check: PassMIT
Migrate Dotnet9 To Dotnet10dotnet/skills5.6k2 repos~4.8kAutomated safety check: PassMIT

Similar skills

  • Installs or refreshes Iron Proxy and its Iron Control web console for NanoClaw, with a local Docker setup, database, credentials and a human approval bridge.

    31k GitHub stars~4.6k tokensUpdated today
    DevOps & CloudAuto-check: notes
  • A skill your agent uses when editing, adding, or reviewing any file under .github/workflows/, or when a CI step installs a CLI tool (npm i -g, npx, pipx, uses: /setup-).

    1.1k GitHub stars~1.9k tokensUpdated yesterday
    DevOps & CloudAuto-check passed
  • AWS Cloud Advisor

    tech-leads-club/agent-skills

    Answers AWS architecture, security and service-selection questions by searching AWS documentation through MCP tools first, then adapting advice to your stack and team.

    7k GitHub stars~2.1k tokensUpdated yesterday
    DevOps & CloudAuto-check passed
  • KubeShark for Kubernetes

    LukasNiessen/kubernetes-skill

    Keeps Kubernetes manifests, Helm charts and policies grounded by diagnosing six failure modes, such as insecure defaults and API drift, and loading only matching references.

    446 GitHub stars~1.2k tokensUpdated 28 days ago
    DevOps & CloudAuto-check passed
  • Official

    Migrate a .NET 9 project or solution to .NET 10 and resolve all breaking changes.

    5.6k GitHub starsUsed in 2 repos~4.8k tokens
    DevOps & CloudAuto-check passed
  • Censorship Audit

    hedioum/Hedioum-Pool-Tunnel

    Audit and harden the Hedioum Pool Tunnel against nation-state DPI and censorship, as a filtering/anti-censorship expert would.

    139 GitHub stars~4.9k tokensUpdated 1 mo ago
    DevOps & CloudAuto-check passed

More from mukul975/Anthropic-Cybersecurity-Skills

All 644 skills in this repo
  • Campaign Attribution Evidence Analysis

    mukul975/Anthropic-Cybersecurity-Skills

    Weighs infrastructure, TTP, malware code and timing evidence with the Diamond Model and competing hypotheses to reach a confidence-rated attribution.

    34k GitHub stars~2.3k tokensUpdated 1 mo ago
    Auto-check passed
  • Go Malware Analysis in Ghidra

    mukul975/Anthropic-Cybersecurity-Skills

    Walks through reverse engineering Go-compiled malware in Ghidra: parsing buildinfo and pclntab, recovering stripped function names and extracting dependencies.

    34k GitHub stars~2.8k tokensUpdated 1 mo ago
    Auto-check passed
  • LNK and Jump List Forensics

    mukul975/Anthropic-Cybersecurity-Skills

    Guides forensic analysis of Windows LNK shortcut files and Jump Lists with LECmd, JLECmd and manual parsing to show file access and program execution.

    34k GitHub stars~2.8k tokensUpdated 1 mo ago
    Auto-check passed
  • Malware Persistence Analysis with Autoruns

    mukul975/Anthropic-Cybersecurity-Skills

    Hunts Windows malware persistence with Sysinternals Autoruns, covering run keys, services, scheduled tasks and drivers, with baseline comparison.

    34k GitHub stars~1.2k tokensUpdated 1 mo ago
    Auto-check passed
  • NTFS MFT Deleted File Recovery

    mukul975/Anthropic-Cybersecurity-Skills

    Guides a Windows forensic examination of the NTFS Master File Table to recover deleted-file evidence, build timelines and spot timestomping.

    34k GitHub stars~2.7k tokensUpdated 1 mo ago
    Auto-check passed
  • Network Covert Channel Analysis

    mukul975/Anthropic-Cybersecurity-Skills

    Detects DNS tunneling, ICMP exfiltration and HTTP-based covert channels in packet captures and DNS logs when hunting for hidden command-and-control traffic.

    34k GitHub stars~2k tokensUpdated 1 mo ago
    Auto-check passed

Questions about Performing Dark Web Monitoring For Threats

What does Performing Dark Web Monitoring For Threats do?

Dark web monitoring involves systematically scanning Tor hidden services, underground forums, paste sites, and dark web marketplaces to identify threats targeting an organization, including leaked cre. Performing Dark Web Monitoring For Threats is an agent skill from mukul975/Anthropic-Cybersecurity-Skills.

When should I use Performing Dark Web Monitoring For Threats?

Performing Dark Web Monitoring For Threats fits situations like: devOps & Cloud work in your project.

How do I install Performing Dark Web Monitoring For Threats in Claude Code?

Run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill performing-dark-web-monitoring-for-threats -a claude-code`. Or copy the skill folder (skills/performing-dark-web-monitoring-for-threats in mukul975/Anthropic-Cybersecurity-Skills) into .claude/skills/performing-dark-web-monitoring-for-threats in your project. Claude Code loads it when a task matches its description.

How do I install Performing Dark Web Monitoring For Threats in Codex?

Run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill performing-dark-web-monitoring-for-threats -a codex`. Or copy the skill folder (skills/performing-dark-web-monitoring-for-threats in mukul975/Anthropic-Cybersecurity-Skills) into .agents/skills/performing-dark-web-monitoring-for-threats in your project. Codex loads it when a task matches its description.

Can I use Performing Dark Web Monitoring For Threats in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill performing-dark-web-monitoring-for-threats -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/performing-dark-web-monitoring-for-threats, .gemini/skills/performing-dark-web-monitoring-for-threats, .github/skills/performing-dark-web-monitoring-for-threats and .opencode/skills/performing-dark-web-monitoring-for-threats in your project.

What does Performing Dark Web Monitoring For Threats need to run?

Going by SKILL.md and its folder, Performing Dark Web Monitoring For Threats needs Python for the scripts in its folder. Our summary lists: Python 3; A credential in YOUR_HIBP_KEY.

Does Performing Dark Web Monitoring For Threats access the network?

SKILL.md names 8 domains. In commands or code: haveibeenpwned.com, check.torproject.org and raw.githubusercontent.com; the agent is likely to contact these when it follows the instructions. As links in the text: torproject.org, github.com, darkowl.com, intel471.com and flare.io. This is read from the text; nothing was executed.

Is Performing Dark Web Monitoring For Threats safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Performing Dark Web Monitoring For Threats use?

Performing Dark Web Monitoring For Threats is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Performing Dark Web Monitoring For Threats use?

About 2.5k tokens (SKILL.md is roughly 9.9k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 2.3k tokens, read only when the agent opens those files.

What are the alternatives to Performing Dark Web Monitoring For Threats?

Skills that share tags, products or a category with Performing Dark Web Monitoring For Threats: Iron Proxy Gateway for NanoClaw (nanocoai/nanoclaw, 31k stars), GitHub Actions Supply Chain Pinning (asyncapi/generator, 1.1k stars), AWS Cloud Advisor (tech-leads-club/agent-skills, 7k stars) and KubeShark for Kubernetes (LukasNiessen/kubernetes-skill, 446 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Performing Dark Web Monitoring For Threats?

mukul975 (a GitHub user) maintains it in mukul975/Anthropic-Cybersecurity-Skills, which has 34,116 GitHub stars. The repository holds 644 skills in this directory. The repository was last updated on August 31, 2026.

Source: mukul975/Anthropic-Cybersecurity-Skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.