This website uses cookies

Read our Privacy policy and Terms of use for more information.

AI-assisted content
 
Block
06 · Foundations and Tradecraft
 
 
Topic
Dark Web Access
 
 
Tools
Tor Browser · Tails OS · Ahmia
 
 
Difficulty
Adversarial-grade
 
Prerequisites

Mobile location intelligence: advertising IDs and BSSID.

01

The dark web is a legal environment, not a lawless one

Investigators who treat the dark web as inherently off-limits miss evidence that is publicly accessible under the same legal frameworks that govern open-web research. Those who treat it as a consequence-free zone face prosecution, professional sanction, and source compromise.

The dark web is a collection of networks, principally Tor onion services, that require specific software to access. It is not illegal to visit. The distinction that matters is not which network you use but what you do on it: the same acts that are illegal on the open web are illegal on the dark web, and vice versa.

What changes is the risk profile. Operational security failures that are minor on the open web can expose sources or trigger law enforcement attention. The legal frameworks governing your work (GDPR, the CFAA, the UK CMA) do not switch off when you connect to Tor. Understanding where the legal lines sit is the prerequisite for dark web investigative work.

In the field

On 8 November 2024, Finastra, a financial software and services provider to 45 of the world's top 50 banks, notified customers that a threat actor had communicated on the dark web claiming to have exfiltrated data from its internal file transfer platform. Security journalist Brian Krebs reported the incident publicly on 19 November, before which no public disclosure had been made.

  • Threat intelligence forum capture. The seller listed data from Finastra's banking clients on the cybercrime forum BreachForums on 31 October and again, naming Finastra directly, on 8 November; screenshots of both listings were captured by the threat intelligence platform Ke-la.com.
  • Source corroboration. A Finastra customer independently shared a copy of the company's internal disclosure notice with Krebs, corroborating the threat actor's claim from a second, non-public channel.
  • On-record confirmation. Finastra provided a written statement confirming the incident and its response, stating that initial evidence pointed to compromised credentials.
KrebsOnSecurity · Fintech Giant Finastra Investigating Data Breach · 19 November 2024

Learning outcomes

By the end of this tutorial you will be able to:

  • Identify which actions on the dark web are legally equivalent to open-web actions and which carry additional legal exposure

  • Apply the Computer Misuse Act (UK), CFAA (US), and GDPR Article 6 frameworks to specific dark web investigative scenarios

  • Distinguish between passive access (lawful in almost all jurisdictions) and active interaction (requires case-by-case legal review)

  • Construct a compartmentalised Tor access environment that does not expose real IP, device identity, or institutional affiliation

  • Document dark web evidence to an evidentiary standard acceptable in UK and EU court proceedings

logo

The rest of this tutorial is for Signal subscribers.

What remains: the decision framework, the tool configuration, the failure modes, and the evidentiary standard required to use the finding defensibly. Signal is €90 a year, or €9 a month. Students, €49 a year.

Join Signal

A Signal subscription gives you:

  • Full OSINT Reference Card library, 21 domains
  • Methods, every tradecraft tutorial in full
  • AI in OSINT, every prompt and field report
  • Shadow Analysis, every forensic dossier