deepdarkCTI is a curated collection of Cyber Threat Intelligence sources accessible through the deep and dark web.
The project addresses the need to systematically identify and catalog intelligence sources that operate in hidden internet spaces relevant to threat analysis. It collects references to Telegram channels and groups, Discord servers, ransomware gang websites, cybercriminal forums, data leak marketplaces, exploit databases, Twitter accounts, and Ransomware-as-a-Service sites. The README describes methods for searching and analyzing these sources to support the three levels of threat intelligence work: strategic analysis of organizational security posture, tactical understanding of adversary techniques and procedures, and operational intelligence about specific threats.
Organizations conducting threat intelligence operations should adopt this tool if they need structured access to deep and dark web intelligence sources as part of their OSINT program. It suits teams already engaged in threat hunting and analysis who want a centralized reference for where relevant intelligence surfaces. The project explicitly positions itself as an OSINT-focused collection rather than a replacement for commercial threat feeds or automated monitoring systems.
The project maintains an active community channel on Telegram where contributors propose new sources and discuss research tactics. The maintainers have established transparent donation mechanisms to fund project development. Development appears driven by direct community input, with contributors from the threat intelligence field actively shaping which sources get added to the collection.