- Only 0.01% of the Internet is accessible through the Dark Web
- More than 2.5 million users access TOR daily
- 62% of the Dark Web is used for legal services
- The amount of illegal transactions in 2023 exceeded $14 billion
- Over 30,000 active .onion sites in 2024
Main Darknets
1. TOR (The Onion Router)
- Statistics:
- 6000+ relay server
- 2000+ exit nodes
- Bandwidth total: 500+ Gbps
- Access: torproject.org
- Characteristics:
- Onion Routing (3+ knots)
- Hidden services (.onion)
- Bridge relay for censored countries
2. I2P (Invisible Internet Project)
- Statistics:
- 55,000+ active routers
- Growth of 40% in 2023
- Access: geti2p.net
- Characteristics:
- Garlic routing
- Eepsite (.i2p)
- Integrated applications
3. Freenet
- Statistics:
- Distributed Storage
- 10,000+ active nodes
- Access: freenetproject.org
- Characteristics:
- Freesites
- Darknet mode
- Friend-to-friend networking
4. ZeroNet
- Statistics:
- 100,000+ sites
- Decentralised
- Access: zeronet.io
- Characteristics:
- Bitcoin auth
- Torrent-like hosting
- No central server
Architecture and Operation
TOR Network
[Client] → [Guard Node] → [Middle Node] → [Exit Node] → [Destination]
(encrypted) (encrypted) (decrypted)
I2P Network
[Client] → [Inbound Tunnels] → [Network Database] → [Outbound Tunnels] → [Destination]
(garlic encrypted) (distributed DHT) (garlic encrypted)
Use Cases Legal
- Journalism
- Source Protection
- Bypass censorship
- Safe Whistleblowing
- Privacy
- Private communications
- Protection of personal data
- Bypass surveillance
- Research
- OSINT
- Threat Intelligence
- Security Research
Essential instruments
1. Browser and Client
# TOR Browser hardening
about:config
network.security.ports.banned
network.proxy.socks_remote_dns
2. Security Tools
# Tails OS persistence
sudo tails-persistence-setup
# Whonix gateway config
sudo whonix_gateway
3. OPSEC Tools
# PGP key generation
gpg --full-generate-key --expert
# Verify onion addresses
curl --socks5-hostname localhost:9050
Threat Model
1. Common Attacks
- Exit Node Monitoring
- Correlation Attacks
- Traffic Analysis
- De-anonymization
2. Countermeasures
# Example: Check for exit node manipulation
def check_exit_node(onion_service):
with Controller.from_port() as controller:
circuit = controller.get_circuit(onion_service)
exit_node = circuit.path[-1]
return verify_node_fingerprint(exit_node)
Best Practices
1. OPSEC Guidelines
# Separate identities
torsocks-shell unique_identity_1
# Verify connection
curl --socks5-hostname localhost:9050 check.torproject.org
2. Operational Safety
- Compaction
- Air-gapped systems
- Clean room environment
Monitoring and Detection
1. Network Traffic
# Example: Monitor for TOR traffic
def detect_tor_traffic(pcap_file):
packets = rdpcap(pcap_file)
tor_signatures = [
b'tor-browser',
b'tor-relay',
b'.onion'
]
for packet in packets:
if TCP in packet and packet[TCP].dport == 9050:
return True
for sig in tor_signatures:
if sig in raw(packet):
return True
return False
2. Endpoint Security
# Check for TOR processes
ps aux | grep tor
# Monitor network connections
netstat -tupln | grep ESTABLISHED
Resources and Useful Links
1. Research and Training
2. Security Tools
3. Research Papers
- "Tor: The Second-Generation Onion Router"
- "I2P: A Scalable Framework for Anonymous Communication"
- "Understanding Darknet Markets"
Monitoring & Intelligence
OSINT Tools
# Example: Onion crawler
from stem import Signal
from stem.control import Controller
def crawl_onion(onion_address):
with Controller.from_port() as controller:
controller.authenticate()
try:
response = requests.get(
onion_address,
proxies={'http': 'socks5h://127.0.0.1:9050',
'https': 'socks5h://127.0.0.1:9050'}
)
return response.text
except Exception as e:
print(f"Error: {e}")
controller.signal(Signal.NEWNYM)
Best Security Practices
- Operating System
- Tails OS for maximum safety
- Whonix for isolation
- Virtual Machine dedicated
- Communication
- PGP for messages
- OTR per chat
- Secure Drop per file
- OPSEC
- VPN + Tor
- Different identities
- Air-gapped systems
Conclusions
The Dark Web is a powerful tool that requires:
- In-depth technical understanding
- Rigid safety practices
- Risk awareness
- Responsible use




