fastfire/deepdarkcti

Collection of Cyber Threat Intelligence sources from the deep and dark web

View on GitHub ↗Jump to charts ↓

Summary Information

Updated 44 minutes ago
Added to GitGenius on September 9th, 2026
Created on May 29th, 2021
Open Issues & Pull Requests: 87 (+0)
GitHub issues: Enabled
Number of forks: 1,211
Total Stargazers: 7,264 (+0)
Total Subscribers: 259 (+0)

Repository Insights (GitGenius)

Median issue/PR response: 6.0 days
Mean response time: 23.0 days
90th percentile: 133.4 days
Tracked items: 9

Charts & Analytics

Fetching additional details & charts...

Issue Activity (beta)

Open issues: 13
New in 7 days: 0
Closed in 7 days: 0
Avg open age: 491 days
Stale 30+ days: 12
Stale 90+ days: 12

Recent activity

Opened in 7 days: 0
Closed in 7 days: 0
Comments in 7 days: 0
Events in 7 days: 0

Top labels

No label distribution available yet.

Most active issues this week

Detailed Description

deepdarkCTI is a curated collection of Cyber Threat Intelligence sources accessible through the deep and dark web.

The project addresses the need to systematically identify and catalog intelligence sources that operate in hidden internet spaces relevant to threat analysis. It collects references to Telegram channels and groups, Discord servers, ransomware gang websites, cybercriminal forums, data leak marketplaces, exploit databases, Twitter accounts, and Ransomware-as-a-Service sites. The README describes methods for searching and analyzing these sources to support the three levels of threat intelligence work: strategic analysis of organizational security posture, tactical understanding of adversary techniques and procedures, and operational intelligence about specific threats.

Organizations conducting threat intelligence operations should adopt this tool if they need structured access to deep and dark web intelligence sources as part of their OSINT program. It suits teams already engaged in threat hunting and analysis who want a centralized reference for where relevant intelligence surfaces. The project explicitly positions itself as an OSINT-focused collection rather than a replacement for commercial threat feeds or automated monitoring systems.

The project maintains an active community channel on Telegram where contributors propose new sources and discuss research tactics. The maintainers have established transparent donation mechanisms to fund project development. Development appears driven by direct community input, with contributors from the threat intelligence field actively shaping which sources get added to the collection.