ENNAENNA

OnionScan

๐Ÿ”Ž General OSINT ยท Go

OnionScan is a tool for investigating dark web hidden services (.onion sites) for operational security weaknesses. It identifies information leaks that could deanonymize hidden service operators, including exposed server status pages, analytics tracking codes, EXIF metadata in images, SSH fingerprints, email addresses, Bitcoin addresses, leaked IP addresses in headers, and linked clearnet infrastructure. OnionScan correlates findings across multiple hidden services to identify common operators. It is used by researchers and law enforcement to investigate dark web infrastructure and by operators to audit their own hidden services for OPSEC failures.

3.2kstars
633forks
86issues
Updated 1y ago
+I use this

Installation

$ go install github.com/s-rah/onionscan@latest

Use Cases

  • Investigating dark web hidden services for OPSEC leaks
  • Correlating multiple .onion sites to common operators
  • Auditing hidden service configurations for information exposure
  • Discovering clearnet infrastructure linked to onion services

Tags

dark-webtoropsec-audithidden-servicesdeanonymization

Community Reviews

More in General OSINT