{"id":2111,"date":"2021-07-17T08:15:19","date_gmt":"2021-07-17T08:15:19","guid":{"rendered":"https:\/\/osintme.com\/?p=2111"},"modified":"2021-07-17T08:17:45","modified_gmt":"2021-07-17T08:17:45","slug":"scraping-the-darkwebs-onions-interview-with-doctor-chaos","status":"publish","type":"post","link":"https:\/\/osintme.com\/index.php\/2021\/07\/17\/scraping-the-darkwebs-onions-interview-with-doctor-chaos\/","title":{"rendered":"Scraping the darkweb&#8217;s .onions &#8211; interview with Doctor Chaos"},"content":{"rendered":"\t\t<div data-elementor-type=\"wp-post\" data-elementor-id=\"2111\" class=\"elementor elementor-2111\">\n\t\t\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-ac4d79b elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"ac4d79b\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-03e00a2\" data-id=\"03e00a2\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-57f797f elementor-widget elementor-widget-text-editor\" data-id=\"57f797f\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p>This time I have a fascinating interview with a fellow infosec community member, a pentester and the creator of <a href=\"https:\/\/osint.party\/\">osint.party<\/a>, a research project to keep track of websites on the Tor network &#8211; <a href=\"https:\/\/twitter.com\/ChaosD0c\">Doctor Chaos<\/a>.<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-b16269c elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"b16269c\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-979f7ae\" data-id=\"979f7ae\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-1bc79a7 elementor-widget elementor-widget-testimonial\" data-id=\"1bc79a7\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"testimonial.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t<div class=\"elementor-testimonial-wrapper\">\n\t\t\t\t\t\t\t<div class=\"elementor-testimonial-content\">If there is any law enforcement, other government agency or even corporations out there that wants to know more about my research, work and other cool things that I've found - please reach out.<\/div>\n\t\t\t\n\t\t\t\t\t\t<div class=\"elementor-testimonial-meta elementor-has-image elementor-testimonial-image-position-aside\">\n\t\t\t\t<div class=\"elementor-testimonial-meta-inner\">\n\t\t\t\t\t\t\t\t\t\t\t<div class=\"elementor-testimonial-image\">\n\t\t\t\t\t\t\t<img fetchpriority=\"high\" decoding=\"async\" width=\"400\" height=\"400\" src=\"https:\/\/i0.wp.com\/osintme.com\/wp-content\/uploads\/2021\/07\/doctor-chaos-osint-party.jpg?fit=400%2C400&amp;ssl=1\" class=\"attachment-full size-full wp-image-2163\" alt=\"doctor chaos osint party\" srcset=\"https:\/\/i0.wp.com\/osintme.com\/wp-content\/uploads\/2021\/07\/doctor-chaos-osint-party.jpg?w=400&amp;ssl=1 400w, https:\/\/i0.wp.com\/osintme.com\/wp-content\/uploads\/2021\/07\/doctor-chaos-osint-party.jpg?resize=300%2C300&amp;ssl=1 300w, https:\/\/i0.wp.com\/osintme.com\/wp-content\/uploads\/2021\/07\/doctor-chaos-osint-party.jpg?resize=150%2C150&amp;ssl=1 150w\" sizes=\"(max-width: 400px) 100vw, 400px\" \/>\t\t\t\t\t\t<\/div>\n\t\t\t\t\t\n\t\t\t\t\t\t\t\t\t\t<div class=\"elementor-testimonial-details\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t<div class=\"elementor-testimonial-name\">Doctor Chaos<\/div>\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<div class=\"elementor-testimonial-job\">creator of osint.party<\/div>\n\t\t\t\t\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-02fa3b6 elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"02fa3b6\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-e4859ca\" data-id=\"e4859ca\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-0551c3c elementor-widget elementor-widget-text-editor\" data-id=\"0551c3c\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p><strong>Standard beginning &#8211; who are you, what&#8217;s your background, what&#8217;s your experience and motivation?<\/strong><\/p><p>I&#8217;m Doctor Chaos. I became a penetration tester by accident about 10 years ago and I&#8217;ve been doing it professionally ever since. I recently decided to do more OSINT work in my free time to help out the community and spend some time building software that helps others catch bad people.<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-556c216 elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"556c216\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-775f3e4\" data-id=\"775f3e4\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-adc95b1 elementor-widget elementor-widget-text-editor\" data-id=\"adc95b1\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p><strong>What is OSINT.PARTY?<\/strong><\/p><p><a href=\"https:\/\/osint.party\/\">OSINT.PARTY<\/a> is my current side project, it slowly evolved over time from a small crawler that finds new and interesting onions to a complete metadata collection project. I eventually decided to publish my work and share it with others to see if anyone else could use the data to find interesting things on Tor.<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-f594dfa elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"f594dfa\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-4c8ba99\" data-id=\"4c8ba99\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-a21c5f4 elementor-widget elementor-widget-text-editor\" data-id=\"a21c5f4\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p><strong>So what&#8217;s the history behind this project?<\/strong><\/p><p>OSINT.PARTY initially started early \/ mid 2020 as a hobby project of mine to track things around the Tor network. At some point I started sharing various screenshots and bits of data on OSINT \/ Threat Intel related discords and people seemed very interested so early 2021 I decided to launch the project publicly.<\/p><p>The project currently consists of a simple crawler that checks every single onion address in the database for up\/downtime and it extracts some bits of meaningful metadata like HTTP headers, specific HTML tags, and other content like email addresses, BTC addresses and it tries to automatically de-anonimize the website if possible.<\/p><p>At this time, the database has roughly 40 million metadata records.<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-fa78099 elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"fa78099\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-b71db03\" data-id=\"b71db03\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-825736d elementor-widget elementor-widget-image\" data-id=\"825736d\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"image.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<img decoding=\"async\" width=\"207\" height=\"310\" src=\"https:\/\/i0.wp.com\/osintme.com\/wp-content\/uploads\/2021\/06\/osint-party.png?fit=207%2C310&amp;ssl=1\" class=\"attachment-large size-large wp-image-2137\" alt=\"osint party\" srcset=\"https:\/\/i0.wp.com\/osintme.com\/wp-content\/uploads\/2021\/06\/osint-party.png?w=207&amp;ssl=1 207w, https:\/\/i0.wp.com\/osintme.com\/wp-content\/uploads\/2021\/06\/osint-party.png?resize=200%2C300&amp;ssl=1 200w\" sizes=\"(max-width: 207px) 100vw, 207px\" \/>\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-f109a43 elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"f109a43\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-0cbccc8\" data-id=\"0cbccc8\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-5b30cb4 elementor-widget elementor-widget-text-editor\" data-id=\"5b30cb4\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p><strong>How can one use your platform \/ service \/ whatever you refer to it as? Is there a cost? What are the benefits?<\/strong><\/p><p>The platform is currently quite bare. There are a few API endpoints to retrieve basic metadata about a onion address and there are a few endpoints to run search queries for BTC addresses, email addresses and SSH keys. I&#8217;ve also recently added support for direct integration with Maltego so users can directly use my tools in their existing workflow.<\/p><p>Outside of just crawling OSINT.PARTY also exposes both a HTTP and a Maltego API endpoint that lets researchers and interested people query on the data in my dataset. It&#8217;s a bit rough but I&#8217;m planning to eventually work on a GUI and turn this into a Shodan-like product.<\/p><p>There are also a few other features in the pipeline such as full text &amp; title search once I figure out how to deal with CSAM and work around the rules &amp; regulations.<\/p><p>The project is always evolving and I&#8217;m always open to suggestions and new ideas from users. Give it a try and see if there is something you are missing : &#8211; )<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-5956461 elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"5956461\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-757b8e3\" data-id=\"757b8e3\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-796326a elementor-widget elementor-widget-text-editor\" data-id=\"796326a\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p><strong>What is your methodology for researching the darkweb entities and why do it in the first place?<\/strong><\/p><p>I collect as much metadata as I can and start correlating data with data that I find elsewhere. I mainly focus on de-anonimizing servers and websites because that usually leads to arrests \ud83d\ude42<\/p><p>As to why &#8211; it&#8217;s because I enjoy chasing malicious actors. Finding out where their servers are hosted and figuring out how terrible their OPSEC is only to then share it with law enforcement and seeing the website go offline a few weeks or months later. I hope to one day be able to turn it into a job and pwn markets all day \ud83d\ude42<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-9753473 elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"9753473\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-6e40870\" data-id=\"6e40870\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-50b9bd5 elementor-widget elementor-widget-text-editor\" data-id=\"50b9bd5\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p><strong>What learning resources would you recommend to people who are interested in darkweb investigations?<\/strong><\/p><p>It really depends on what you are after, if you just want to de-anonimize servers familiarize yourself with the basics of how web applications function, sometimes a application might have to call to external resources to retrieve a image or a URl that you provide. There are a few good blog posts out there that explain these basic principles &#8211; <a href=\"https:\/\/pielco11.ovh\/posts\/cloud-hunting\/\">like this<\/a>.<\/p><p>For myself &#8211; I always look at investigations from a metadata perspective. I try to collect everything out there and just put it into a big Maltego project.<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-3c5ecc0 elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"3c5ecc0\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-088ffcc\" data-id=\"088ffcc\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-20d56e2 elementor-widget elementor-widget-text-editor\" data-id=\"20d56e2\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p><strong>What is the most outrageous \/ strangest thing you encountered on the darkweb?<\/strong><\/p><p>A Russian carding operation that had failed to properly protect their admin interface allowing a malicious actor to drain their hot Monero and BTC wallets.<\/p><p>I&#8217;ve recently started running more invasive de-anonimization scans that involve looking for SVN, GIT and HG directories that are served on the web. Via this I managed to de-anonimize a specific carding shop and extract their full source code, the names of the authors and the location of their build server.<\/p><p>I&#8217;ve passed this information on to some friends in law enforcement and started browsing around the code.<\/p><p>At some point I figured out that they had a few unprotected endpoints that allow direct withdrawals of the BTC &amp; XMR in their hot wallets. I&#8217;ve never done anything with it but I suspect others might have as I&#8217;ve seen the admins hastily change or remove the endpoints.<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-fe1334c elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"fe1334c\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-12d9c80\" data-id=\"12d9c80\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-cd6c884 elementor-widget elementor-widget-text-editor\" data-id=\"cd6c884\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p><strong>How much of the darkweb (in your estimate) is illegal content vs privacy or free speech enabling stuff?<\/strong><\/p><p>I&#8217;d say a large part of the darkweb is just spam, trash and other illegal content. There is very little actual good stuff out there. My tracker has ~100,000 onions and most of those can be classified as phishing sites, fake sites and other malicious contents.<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-a4f5246 elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"a4f5246\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-818fa10\" data-id=\"818fa10\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-a72342c elementor-widget elementor-widget-text-editor\" data-id=\"a72342c\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<div><strong>Do you know any positive or funny darkweb stories? As in, not related to illicit activity?<\/strong><\/div><div>\u00a0<\/div><div>Hmm. One of the more fun Tor stories that I know about is how a college student got nabbed doing a bomb threat\u00a0<a href=\"https:\/\/www.theverge.com\/2013\/12\/18\/5224130\/fbi-agents-tracked-harvard-bomb-threats-across-tor\" target=\"_blank\" rel=\"noreferrer nofollow noopener\">FBI agents tracked Harvard bomb threats despite Tor &#8211; The Verge.<\/a><\/div><div>\u00a0<\/div><div>It basically boils down to &#8220;if you are the only one using Tor and you do something with Tor you are going to get nabbed : &#8211; )&#8221;<\/div>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-56a0ad1 elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"56a0ad1\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-6aa6d5e\" data-id=\"6aa6d5e\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-c0c5b9f elementor-widget elementor-widget-text-editor\" data-id=\"c0c5b9f\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p><strong>Can you share some darkweb opsec tips \/ privacy setup methods for those embarking on darkweb research?<\/strong><\/p><p>Use separate identities. Do everything inside a VM or dedicated computer and take some time off. There is a lot of bad shit out there and sometimes you just need to take some time off a investigation to give your head a break.<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-a598475 elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"a598475\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-e6d1639\" data-id=\"e6d1639\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-cf9e03a elementor-widget elementor-widget-text-editor\" data-id=\"cf9e03a\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<div><strong>What is your daily driver operating system? What do you like seeing in an investigator&#8217;s OS build?<\/strong><\/div><div>\u00a0<\/div><div>My &#8220;daily driver&#8221; for OSINT related stuff is a old Lenovo X230 running Qubes OS with <a title=\"https:\/\/github.com\/osresearch\/heads\" href=\"https:\/\/github.com\/osresearch\/heads\" target=\"_blank\" rel=\"noreferrer nofollow noopener\">Heads<\/a>.<\/div><div>\u00a0<\/div><div>I&#8217;m very paranoid about the physical security of my machines so I&#8217;ve gone above and beyond to build a reasonibly secure workstation that I feel safe leaving unattended at times.<\/div><div>\u00a0<\/div><div>My laptop is covered in tamper evident material, the BIOS &amp; TPM are covered in a big blob of epoxy, \/boot is signed with a PGP key, I&#8217;ve got HOTP and TOTP going and heads pulls various measurements and only releases the FDE key when the measurements + a password match. It&#8217;s a system that I feel safe leaving somewhere unattended \ud83d\ude42<\/div><div>\u00a0<\/div><div>Outside of that I also use a boring Windows 10 workstation because sometimes a gamer needs to play some games.<\/div><div>\u00a0<\/div>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-c0006be elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"c0006be\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-1d344b4\" data-id=\"1d344b4\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-535826b elementor-widget elementor-widget-text-editor\" data-id=\"535826b\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<div><strong>If you were to name 3 favourite privacy-enabling online services &#8211; and what makes them your favourite?<\/strong><\/div><div>\u00a0<\/div><ul><li>Signal &#8211; Tried and tested secure messenger that just works.<\/li><li>Protonmail &#8211; Hosting my own mail always gets quite messy so I&#8217;m just defaulting to Proton despite some odd privacy issues.<\/li><li>Tor &#8211; It stinks. But there is nothing better out there.<\/li><\/ul>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-cf06aac elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"cf06aac\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-936ff53\" data-id=\"936ff53\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-840c45b elementor-widget elementor-widget-text-editor\" data-id=\"840c45b\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p><strong>Whatever else you think is important \/ want to mention or talk about?<\/strong><\/p><p>Yes! If there is any law enforcement, other government agency or even corporations out there that wants to know more about my research, work and other cool things that I&#8217;ve found &#8211; please reach out. I&#8217;d love to share my knowledge with others. The dataset that I have is massive and I love to collaborate with others to knock out bad actors!<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-c8c7b03 elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"c8c7b03\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-7f82430\" data-id=\"7f82430\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-c39926e elementor-widget elementor-widget-text-editor\" data-id=\"c39926e\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p><strong>doc@chaos.institute<\/strong><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-dbb1641 elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"dbb1641\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-d30d7e2\" data-id=\"d30d7e2\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-9ab11d2 elementor-widget elementor-widget-text-editor\" data-id=\"9ab11d2\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p><strong>NOTE: If you work in LE and investigate cybercrime, you absolutely should reach out to Doctor Chaos &#8211; just please remember to use your official LE work email address to contact him.<\/strong><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<\/div>\n\t\t","protected":false},"excerpt":{"rendered":"<p>A fascinating interview with a fellow infosec community member, a pentester and the creator of osint.party, a research project to keep track of websites on the Tor network &#8211; Doctor Chaos.<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"neve_meta_sidebar":"","neve_meta_container":"","neve_meta_enable_content_width":"","neve_meta_content_width":0,"neve_meta_title_alignment":"","neve_meta_author_avatar":"","neve_post_elements_order":"","neve_meta_disable_header":"","neve_meta_disable_footer":"","neve_meta_disable_title":"","_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[90],"tags":[43,44,39,140,79],"class_list":["post-2111","post","type-post","status-publish","format-standard","hentry","category-conversations-debriefs","tag-darknet","tag-intelligence","tag-interview","tag-scraping","tag-website"],"jetpack_featured_media_url":"","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/osintme.com\/index.php\/wp-json\/wp\/v2\/posts\/2111","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/osintme.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/osintme.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/osintme.com\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/osintme.com\/index.php\/wp-json\/wp\/v2\/comments?post=2111"}],"version-history":[{"count":16,"href":"https:\/\/osintme.com\/index.php\/wp-json\/wp\/v2\/posts\/2111\/revisions"}],"predecessor-version":[{"id":2172,"href":"https:\/\/osintme.com\/index.php\/wp-json\/wp\/v2\/posts\/2111\/revisions\/2172"}],"wp:attachment":[{"href":"https:\/\/osintme.com\/index.php\/wp-json\/wp\/v2\/media?parent=2111"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/osintme.com\/index.php\/wp-json\/wp\/v2\/categories?post=2111"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/osintme.com\/index.php\/wp-json\/wp\/v2\/tags?post=2111"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}