DarkSonar API

With cyberattacks increasingly on the rise, organizations need better intelligence to safeguard themselves, employees and customers from incidents such as data breaches and ransomware attacks. This rise in illicit cyber activity only increases the need to protect against and determine the likelihood of these attacks.

DarkSonar, a relative risk rating based on darknet intelligence, measures an organization’s credential exposure on the darknet. DarkSonar enables companies to model risk, understand their weaknesses and anticipate potential cyber incidents. In turn, organizations are able to take mitigating actions to protect themselves from loss of data, profits, and brand reputation.


Want to learn how to monitor your relative risk? Contact us.

DarkOwl Announces Release of DarkSonar to Help Businesses Determine Likelihood of Potential Cyberattacks

April 18, 2023

DarkSonar signals inform internal threat modeling, third party risk management, and cyber insurance underwriting

Denver, Colorado, USA – DarkOwl today announced the release of a new product, DarkSonar API, to help organizations better assess and track their potential cyber risk based on the nature of its exposure on the darknet.

Built on DarkOwl’s proprietary Entity dataset, DarkSonar generates a risk rating that is unique to each company. The algorithm used to generate these signals takes into account key quantitative and qualitative factors over time of organizational exposure of email addresses with associated passwords, and weights each signal accordingly. The result is a quantifiable risk indicator that can help companies and organizations monitor and potentially predict cyberattacks.

In testing internally and with beta partners in the insurtech and third-party risk industries, DarkOwl found an elevated DarkSonar score in the months before a cyberattack in approximately 75% of the cases where a company publicly acknowledged a breachDepending on the companies and the nature of the attacks this percentage was as high as 85% in some instances.

“The darknet contains data critical to understanding criminal behavior and security risk,” said Mark Turnage, CEO of DarkOwl. “To develop DarkSonar, we looked at our own vast dataset of darknet content and focused on what has proven to be the number one attack vector for threat actors—namely credentials with passwords. In doing so, we saw that the magnitude of a company’s credential exposure within our database, and the real-life cyberattacks they experience, have a high correlation. This suggests that DarkSonar has not only a monitoring use, but may also have some predictive qualities. It is a valuable tool every threat intelligence team should use and have available.”

DarkOwl’s partner, SecurityScorecard, also expressed the importance of such a tool – even for small businesses. “We recently conducted research with an independent cyber research institute and found that 98% of organizations have vendor relationships with at least one third-party that has experienced a breach in the last two years,” said Alex Rich, VP of Alliances & Channels at SecurityScorecard. “This only reinforces the need for security teams to prioritize maintaining insight into their entire digital ecosystem, including their supply chain. DarkSonar offers a unique way to signal such risks, which is important for businesses of all sizes.”

DarkSonar API was built to be utilized for self-risk assessments, brand monitoring, vendor risk management, and cyber underwriting and risk rating. As supply chain compromise becomes an increasingly prevalent problem, DarkSonar is a means to continually monitor for third-party risk.


To learn more about DarkSonar, please visit https://www.darkowl.com/products/darksonar-api/

[Flipbook] Dark Web Monitoring

When it comes to monitoring the dark web, you need access to technology that you can be confident will notify you when you or your customers’ sensitive information has been exposed. Reduce analyst time and boost efficiency with DarkOwl’s streamlined monitoring functionalities.

When you choose to monitor the dark web using DarkOwl, you have continuous access and insight into the world’s largest breadth of dark web coverage. Learn more about DarkOwl, the dark web, DarkOwl data sources and commonly monitored for items in the flipbook below.


Interested how DarkOwl can monitor the dark web for your business or customers? Contact us.

Entity Explore Boosts Efficiency for Dark Web Threat Intelligence Analysts

DarkOwl Vision UI’s “Entity Explore” enables end-users to gain more relevant insights from their vast dataset of dark web content.

Entity Explore is a dashboard within Vision UI that shows results for queries around tokenized objects with critical contextual information, allowing analyst and threat intelligence teams to truly focus on actionable dark web content that is vital to their business.

The dashboard also incorporates new features geared toward increasing analyst efficiency and functionality, enabling things such as ease of exporting and parsing of information to best lead users towards actionable intelligence.


For those in charge of monitoring for critical information regarding their business or their customers, having access to DarkOwl’s darknet data means access to near real-time data from exclusive dark web sources including authenticated forums and emerging chat networks. Contact us to learn more.

HWG Renews DarkOwl Partnership to Give Clients Continued Access to Sophisticated Dark Web Monitoring

February 16, 2023

Denver, CO – February 16, 2023 – Denver-based dark web data provider DarkOwl is proud to announce the renewal of their partnership with HWG, an Italian-headquartered cybersecurity company that specializes in providing analyst driven cybersecurity solutions and consulting services.

HWG maintains a team of cybersecurity experts to monitor customer digital environments in order to prevent, detect, analyze, and respond to cyber threats. In continuing to partner with DarkOwl, the industry leader in actionable dark web data, HWG is able to offer deep insight into darknet intelligence while monitoring companies’ information systems, detecting anomalies, and containing and responding to cyberattacks.

HWG has used DarkOwl’s darknet data for critical insights such as:

  • Credential Leakage: proactive monitoring of customer-related domains to identify possible compromised credentials on the dark web.
  • Company Reputation: proactive monitoring of brands to understand if there are targeted arguments containing possible related risks.
  • VIP Exposure: proactive monitoring of names and emails of the client’s C-level employees.

Per a statement from HWG CEO Enrico Orlandi, this continued partnership is largely because HWG considers DarkOwl to be an important ally in their mission to fight against cybercrime and protect their customers from potential attacks.

“It is essential for our business to have partners that allow us to offer our clients a top-quality service,” Orlandi announced. “DarkOwl is one of these partners thanks to their extensive knowledge of the darknet and the massive database of dark web content. Their data is critical for us to provide and improve a service that truly matches the needs of businesses to prevent and mitigate cyberattacks.”

Mark Turnage, CEO of DarkOwl, also commented “By renewing this partnership, HWG is demonstrating to their customers that they are committed to offering the most sophisticated cybersecurity solutions to support their suite of services through the Security Operations Center.”

About HWG 

Founded in 2008, HWG provides cyber security operations and consulting services to large and midsize enterprises with advanced security requirements, that don’t plan to keep security expert teams and infrastructure internally. As a trusted security provider for companies in over 20 countries, HWG knows how to improve cybersecurity resilience even across complex and sensitive environments like financial, automotive, industrial, telecom and others.  For more information, visit https://www.hwg.it/en

About DarkOwl 

DarkOwl uses machine learning and human analysts to collect automatically, continuously, and anonymously, index and rank darknet, deep web, and high-risk surface net data that allows for simplicity in searching. DarkOwl is unique not only in the depth and breadth of its darknet data, but also in the relevance and searchability of its data, its investigation tools, and its passionate customer service. DarkOwl data is ethically and safely collected from the darknet, allowing users secure and anonymous access to information and threats relevant to their mission. For more information, visit www.darkowl.com.

Siren Announces New Data Integration Partnership with DarkOwl

Access DarkOwl’s Darknet Data Directly via the Siren Platform

February 09, 2023

Galway, Ireland – February 9, 2023 – Siren, an industry leader in investigative analytics, on a mission to keep people, assets and networks safe, today announced its strategic partnership with DarkOwl, a Denver based threat intelligence company specializing in dark web data.

By fusing together data from open source, vendor and classified sources, Siren enables investigators and data scientists to analyze risks, including threats to national security, public safety, fraud, and compliance, as well as threats to large enterprise corporations. Using the Siren Graph Browser, researchers can string together findings from previously disparate data sources to conduct robust OSINT investigations. 

While much of the power behind Siren’s data products stem from an ability to visualize and integrate data, Siren also curates a strategic selection of Technology Partners that end-users can leverage within their Siren dashboard. Siren has selected DarkOwl as one of these partners as a response to customer needs for cutting-edge data sources, including the darknet and deep web. 

DarkOwl is known in the industry for its extensive coverage of near real-time content from the darknet and related sources. This includes Tor, I2P, chat platforms, ransomware blogs, gaming message archives, paste-sites, and darknet marketplaces. Their data offers insight into these high-risk areas of digital activity, including coverage of emerging darknets and forums requiring authenticated access. 

“By choosing to integrate DarkOwl’s data into their platform, Siren is making a statement that they understand how crucial the darknet is to modern OSINT investigations,” commented DarkOwl CEO Mark Turnage. “Now, investigators can take information from our data set, such as a bitcoin address or a user alias, and pivot using Siren Graph to turn that data into actionable intelligence.”

 “This partnership will offer Siren customers curated access to the dark web,” said John Randles, CEO of Siren. “Now, threat intelligence analysts will have the means to connect DarkOwl data to other forensic, OSINT, company or internal sources of data, to power a variety of Law Enforcement, National Security and Corporate Fraud use cases.”

About Siren
Siren is a complete investigation solution, safeguarding people, assets and networks. Siren fuses data from open source, vendor and classified sources allowing analysts and investigators to analyze risks, threats and crimes for the National Security, Public Safety, Fraud and Compliance, and Cyber Threat communities. Siren’s patented technology is uniquely search based providing the user with easy to use search, analytics, visualization and reporting capabilities for investigations on all data types at all scales of data volume. In 2022, Siren was included in the Deloitte Technology Fast 50. Siren is a Gartner Cool Vendor in an Analytics and Data Science Report in 2020. For more information, visit www.siren.io.

About DarkOwl

DarkOwl uses machine learning and human analysts to collect automatically, continuously, and anonymously collect darkness content. Our products leverage AI to index and rank darknet and deep web data to enhance simplicity in searching. DarkOwl is unique not only in the depth and breadth of its darknet data, but also in its advanced investigation tools and passionate customer service. Our data is ethically and safely collected from the darknet. This allows users secure and anonymous access to information and threats relevant to their mission. For more information, visit www.darkowl.com.

Aditinet Consulting SpA Partners with Dark Web Data Leader DarkOwl to Bolster Cybersecurity Offerings

This dark web data provider partnership will enhance Aditinet customers’ insight into to Supply Chain and Third-Party risk.

December 6, 2022

[Read this release on Webwire]

Denver-based dark web data provider, DarkOwl, and Italy-based cyber security services company, Aditinet Consulting SpA, are pleased to announce their formal strategic partnership. As part of their curated Cyber Security Posture Solutions, this agreement enables Aditinet’s clients to have access to DarkOwl’s near real-time collection of dark web data and make more-informed threat intelligence decisions. 

Aditinet Consulting SpA supports private and public organizations to achieve their business goals through a variety of channels. These include cybersecurity resilience, risk-based consulting, identification and delivery of optimal solutions and fully managed security services, and testing of new solutions and integrations through laboratory and market audits. Aditinet plays an important role in the ongoing scouting of new and emerging cyber security technologies and implementation of in-house best practices at customer sites.

“We are extremely proud to include DarkOwl as one of Aditinet’s main technology data providers and partners,” says Marco Gornati, Sales Director of Aditinet. “Thanks to the important amount of information present in the dark web and analyzed by the DarkOwl platform, we are now able to significantly increase the quality of Supply-Chain Security Posture services that we offer to our customers.” 

Aditinet Consulting’s SpA’s decision to invest in access to DarkOwl’s dark web data – which is known for its exclusive access to authenticated marketplaces and forums – is a response to an evolving cyber threat landscape. Cybersecurity incidents such as malware, ransomware, or insider threats can have massive economical and reputational damages. These incidents, which can often be the result of human error or exposure (such as credentials), impact not just the targeted company, but the entire ecosystem of all involved partners and suppliers. 

“To maintain a full picture of their company’s cyber threat landscape, IT security teams need to have awareness of the risks facing not only themselves, but also their third-party vendors and other members of their organization’s supply chain,” said DarkOwl CEO Mark Turnage. “DarkOwl is proud to work with security services providers who recognize this and choose to add superior darknet offerings to their clientele.”

About Aditinet Consulting SpA 

Aditinet Consulting SpA is an Italian company established in 2004, two major hubs in Milan & Rome and a Service center in Kosovo. Provider for the best blend of best-of-breed Solutions and Services, both pre & post sales, across all the systems lifecycle. Nationwide footprint among the major organizations in CyberSecurity, in mission critical enterprise Network and Data Center infrastructures, supporting new strategic Transformation initiatives.

Major Key Services are on: Technology Consultancy, Design of Systems architecture, Delivery in critical environments, Professional Services for migrations, Assessment (Network-Security), Troubleshooting. 24/7 Assistance Service and NOC/SOC Service.  For more information, visit us at Azienda | Aditinet: networking, security, mobility e cloud

About DarkOwl 

DarkOwl enables organizations to fully understand their security posture, detect potential breaches and violations of the law and mitigate them quickly. DarkOwl turns the dark web data into a tool for our customers, enabling them to quantify risk at scale in order to make decisions that increase business success. By delivering the most prolific, relevant and timely darknet data available, our products ensure that our customers can find the exact data they need. DarkOwl’s robust ecosystem of products turns the dark web into a powerful tool to identify risk at scale and drive better decision making.  We offer a variety of options to access our data, please visit us at  www.darkowl.com

Monitor Cryptocurrency Mentions Using Entity API

Entity API, part of the DarkOwl API product suite, allows users to access highly-targeted, structured information from the largest commercially available collection of darknet and deep web sources, which include Tor, I2P, Zeronet, Data Breaches, encrypted chats, IRC, and authenticated forums. Learn how to monitor cryptocurrency mentions in the datasheet below.

Entity API users are able to search for a crypto address that DarkOwl has captured from darknet sources including illegal marketplaces and vendor forums to detect wallets with problematic activity.


Contact us to learn how Entity API can bolster your security posture.

DarkOwl Releases Entity Explore to Boost Efficiency for Dark Web Threat Intelligence Analysts

November, 2022

DarkOwl Vision UI’s new “Entity Explore” enables end-users to gain more relevant insights from their vast dataset of dark web content.

As part of our continued effort to enhance our dark web data products with features geared towards analyst and threat intelligence teams, DarkOwl is excited to announce our newest product feature, Entity Explore. Launched in the form of a new dashboard within Vision UI, Entity Explore shows results for queries around tokenized objects with critical contextual information.

The dashboard also incorporates new features geared toward increasing analyst efficiency and functionality, enabling things such as ease of exporting and parsing of information to best lead users towards actionable intelligence.

Insight into Dark Web Data is of Increasing Importance

One of the most prevalent use cases for insight into the DarkOwl’s data is the recent persistent rise in ransomware activity, which largely presents itself on the dark web. In 2021, 37% of all business were hit with ransomware – the vast majority of which likely had their sensitive information leaked on underground forums. That same year, over 535M breached credentials associated with Fortune 1000 companies were reportedly circulated on the darknet.

Other recent reporting from Kaspersky maintains that the most common attack vector for all ransomware attacks continues to be via account takeover utilizing stolen or brute forced credentials. The launch of Entity Explore will empower threat intelligence teams with the tools to determine when such account information has been compromised, and take remediation steps accordingly.

Analyst Feedback Leads to Entity Explore Development

Entity Explore was developed as the result of feedback from DarkOwl’s clients, who were seeking an easier way to drill into the dark web exposure and easily export that information for reporting and further analysis. In particular, a number of DarkOwl customers indicated that knowing whether or not a password was identified in tandem with an exposed email address – and having that information returned in the format it appears in its original source – would add value to what they return to their customers.

With Entity Explore, users are now able to extract data from DarkOwl’s collection in a format that has mainly been limited to DarkOwl’s API Customers, such as:

  • Download or see all identified credentials for an email domain query in aggregate format, rather than having to go through individual pages to compile a list
  • Identify all unique mentions of credit cards with a certain BIN
  • Export results from breached data without exporting the entire context of the original dark web page – i.e. only export relevant data based on entity queries.
  • Enhanced reporting functionality centered around ransomware and credential leak content
  • Quickly extract all the email/password combinations for a client
  • Identify and export cryptocurrency addresses for cross-referencing with other internal datafeeds

Per DarkOwl’s CEO Mark Turnage, “Today’s cybersecurity analysts have the burden of juggling a growing number of potential threat vectors that could pose a risk to their organization. Entity Explore makes it simpler to assess what information has been exposed, and what remediation is required as a result.”

Key Features of Vision UI’s Entity Explore

Like other functionalities based on DarkOwl’s Entities, users are able to explore information from the dark web regarding six distinct tokenized objects: Email Domain, Email Address, Credit Card, Bank Identification Number, IP Address, or Cryptocurrency.

Additional highlights from Entity Explore include:

  • Contextual information email queries regarding password data, such as whether a password appears and if it was in plain text or hashed
  • Timeline display depicting results for the queried entity by month
  • Historical look-back for queried data
  • Quantity of results from identified data leaks
  • Overview of source data – e.g. results for this query came from a combination of data leaks and deep web sources
  • Enhanced exporting features to enable easy access to targeted or full result data
  • Simplified dashboard with key information, including crawl date, email, password (if found) and password type (plain text or hashed), link to full result
  • Contextual information regarding credit cards, including a breakdown of unexpired cards, cards with cvv and/or exp date, and cards without details

As of early October, DarkOwl Entity API uncovered and archived  over 9 billion emails, 16 billion credit card numbers, almost 2 billion IP addresses and over 390 million cryptocurrency addresses in the past year.

More Features Geared Towards Threat Intel Teams to Come

Ultimately, the DarkOwl product team understands that our end users need an overall situational awareness of their business’ and client’s dark web footprint. Now, by adding this new explorer feature, threat intel teams can better understand when immediate action needs to be taken on specific accounts, or when they need to triage and flag other related items of importance.

For those in charge of monitoring for critical information regarding their business or their customers, having access to DarkOwl data means access to near real-time data from exclusive dark web sources including authenticated forums and emerging chat networks. For more information about our data or data products, contact us today.


Copyright © 2024 DarkOwl, LLC All rights reserved.
Privacy Policy
DarkOwl is a Denver-based company that provides the world’s largest index of darknet content and the tools to efficiently find leaked or otherwise compromised sensitive data. We shorten the timeframe to detection of compromised data on the darknet, empowering organizations to swiftly detect security gaps and mitigate damage prior to misuse of their data.