Robin The Archaeologist of the Dark Web

Apurv Singh Gautam (Senior Threat Research Analyst · Cyber)

Recon Village @ DEF CON 33 · Day 1 · Recon Village

Overview

In an era where cybercrime increasingly leverages the dark web for illicit activities, the ability to efficiently gather intelligence from these clandestine corners of the internet has become a critical necessity for cybersecurity professionals. Apurv Singh Gautam, a Senior Threat Research Analyst at Cyber, presented "Robin The Archaeologist of the Dark Web" at Recon Village, introducing an innovative AI-powered dark web OSINT tool designed to streamline and automate this often-arduous process. The talk highlighted the limitations of existing, fragmented OSINT tools and proposed a unified solution that integrates searching, filtering, scraping, and analysis into a single, cohesive workflow.

Watch on YouTube

Visual summary for Robin The Archaeologist of the Dark Web by Apurv Singh Gautam
Visual summary for Robin The Archaeologist of the Dark Web by Apurv Singh Gautam

Key moments

  1. 0:00 Introduction, speaker background, and talk agenda
  2. 1:40 Why Dark Web OSINT is a modern necessity
  3. 3:50 Pain points with existing disjointed Dark Web OSINT tools
  4. 5:00 Introducing Robin: The AI-powered Dark Web OSINT tool
  5. 6:30 Robin's architecture overview and LLM support
  6. 7:00 LLM refines user queries for better search results
  7. 8:00 LLM filters 200+ search results to top 20

Robin The Archaeologist of the Dark Web

Speakers: Apurv Singh Gautam, Senior Threat Research Analyst, Cyber

Conference: Recon Village

YouTube: https://www.youtube.com/watch?v=P4p1PyEFzww

Overview

In an era where cybercrime increasingly leverages the dark web for illicit activities, the ability to efficiently gather intelligence from these clandestine corners of the internet has become a critical necessity for cybersecurity professionals. Apurv Singh Gautam, a Senior Threat Research Analyst at Cyber, presented "Robin The Archaeologist of the Dark Web" at Recon Village, introducing an innovative AI-powered dark web OSINT tool designed to streamline and automate this often-arduous process. The talk highlighted the limitations of existing, fragmented OSINT tools and proposed a unified solution that integrates searching, filtering, scraping, and analysis into a single, cohesive workflow.

Robin addresses a significant pain point for threat intelligence analysts: the manual, time-consuming effort involved in navigating dark web forums and marketplaces, identifying relevant information, and compiling comprehensive reports. By leveraging Large Language Models (LLMs), Robin automates query refinement, intelligently filters search results, and generates structured investigative reports, drastically reducing the time and human effort traditionally required for dark web reconnaissance. This tool represents a leap forward in making dark web OSINT more accessible and efficient, enabling defenders to stay ahead of evolving cyber threats.

Background

▶ Watch: Introduction, speaker background, and talk agenda (0:00)

The increasing prevalence of cybercrime necessitates diligent monitoring of the dark web. Cybercrime forums, illicit marketplaces, and ransomware leak sites, many of which reside on .onion domains accessible via The Onion Router (Tor), serve as crucial intelligence sources. However, conducting Open Source Intelligence (OSINT) on the dark web presents unique challenges. The ephemeral nature of many dark web sites, the vast amount of irrelevant data, and the sheer volume of information make manual investigation incredibly inefficient and often overwhelming.

Historically, dark web OSINT has relied on a collection of disparate tools, each specialized for a particular task. As Apurv Singh Gautam noted, his previous talk at SANS in 2021 detailed a comprehensive list of such tools, categorized into search engines, link collections, scanners, and crawlers. The typical workflow involved a multi-stage process:

  1. Link Collection: Using one or more search engines to find relevant .onion links.
  2. Link Filtering: Manually or semi-automatically checking if these links were still active, as many dark web sites are frequently offline.
  3. Data Scraping: Employing another tool to crawl and extract data from the active sites.
  4. Report Generation: Manually sifting through scraped data to identify key insights and compile an investigative report.

This disjointed approach, often requiring analysts to switch between four or five different tools, many written in varying programming languages like Python and Go, created significant inefficiencies. The speaker highlighted the pain points: the need for multiple tools, the time spent on manual link validation, and the hours dedicated to report writing. This fragmentation and the desire to leverage the power of modern LLMs for automated analysis were the primary motivations behind the development of Robin, aiming to consolidate these steps into a single, integrated platform. The name "Robin" itself was inspired by a character from the Japanese manga series One Piece, known for archaeology and uncovering hidden truths.

Key Findings

▶ Watch: Pain points with existing disjointed Dark Web OSINT tools (3:50)

The core contribution of Robin is its successful integration of a multi-stage dark web OSINT workflow into a single, AI-powered tool. The key findings and contributions can be summarized as:

  1. Unified Workflow: Robin consolidates the entire dark web OSINT process—from initial query to final investigative report—into one application. This eliminates the need for analysts to juggle multiple, often incompatible, tools, significantly enhancing efficiency.
  2. AI-Powered Automation: The strategic application of Large Language Models (LLMs) at critical junctures of the OSINT pipeline automates traditionally manual and time-consuming tasks. This includes intelligent query refinement, filtering of search results for relevance, and comprehensive report generation.
  3. Enhanced Relevance Filtering: By employing an LLM to prune a large set of search results (e.g., 200+ links) down to a highly relevant subset (e.g., top 20), Robin ensures that subsequent scraping efforts are focused on valuable data, reducing noise and improving the signal-to-noise ratio.
  4. Structured Investigative Reporting: The tool generates detailed, contextualized reports that prioritize actionable intelligence. These reports explicitly identify artifacts such as cryptocurrency addresses, ransomware names, threat actor aliases, names, emails, and other Personally Identifiable Information (PII), followed by key insights and suggested next steps or example queries for further investigation.
  5. Flexibility and Accessibility: Robin supports multiple major LLM providers (OpenAI, Gemini, Claude) and offers compatibility with local models via Ollama, catering to diverse user preferences and security requirements. It also provides both a Command Line Interface (CLI) for advanced users and an intuitive Graphical User Interface (UI) for broader accessibility.

These findings demonstrate Robin's potential to revolutionize dark web intelligence gathering by making it more automated, precise, and user-friendly, allowing analysts to focus on interpreting intelligence rather than laboring through its collection.

Technical Deep Dive

▶ Watch: Introducing Robin: The AI-powered Dark Web OSINT tool (5:00)

Robin’s architecture is designed to provide a seamless, end-to-end dark web OSINT experience, powered by a series of LLM-driven prompts. The tool operates through four primary functions: searching, filtering, scraping, and analysis, orchestrated by a central control flow.

The process begins with the user interacting via either the CLI or the Web UI. Once a query is entered, Robin initiates its multi-stage intelligence gathering process:

  1. Query Refinement (LLM Prompt #1):

The initial query from the user might be broad (e.g., "ransomware"). Robin first sends this query to an LLM to refine it. The speaker emphasized the importance of a precisely engineered prompt for this step, including instructions like "output just the query." For example, "ransomware" might be refined to "ransomware sites or ransomware threat actors," ensuring more targeted search results. This LLM acts as an intelligent pre-processor, optimizing the subsequent search phase.

  1. Search and Initial Link Collection:

Robin then queries 15 different onion search engines using the refined query. This broad search typically yields a large number of potential links, often 200 or more. Following this, the tool performs an initial check to determine if these collected links are active, filtering out defunct or temporary sites, a common issue on the dark web.

  1. Relevance Filtering (LLM Prompt #2):

Given the large number of links (e.g., 200+) and the high probability of irrelevant results from general search engines, scraping every link is not feasible or efficient. This is where the second LLM prompt comes into play. Robin feeds the LLM a list of titles and URLs, along with an index for each, from the initial search. The prompt instructs the LLM to identify and return only the top 20 most relevant indices (links) based on the original query. The speaker noted that this prompt required significant trial and error, as simply providing titles and URLs led to hallucinations by the LLM. Adding an index and explicitly requesting only the top 20 indices in a structured format (e.g., a table-like backend representation) was crucial to obtaining accurate and consistent results. This step ensures that only the most promising targets proceed to the scraping phase.

  1. Data Scraping:

Once the top 20 relevant and active links are identified, Robin proceeds to scrape the entire content of each associated website. The goal here is to collect as much raw data as possible, which will then be processed for actionable intelligence.

  1. Analysis and Report Generation (LLM Prompt #3):

The scraped data forms the input for the final and most complex LLM prompt, responsible for generating the investigative report. This prompt is meticulously crafted with extensive rules to ensure the output is detailed, contextualized, and analyst-centric. Key instructions embedded in this prompt include:

  • Detailed contextualization: Providing a comprehensive understanding of the scraped content.
  • Indicator Extraction: Explicitly defining what constitutes an "artifact" in the context of cybercrime intelligence. This includes names, emails, other PII, crypto addresses, threat actor aliases, and any other relevant indicators. This explicit definition is crucial because general LLMs are not inherently trained on cybercrime-specific terminology.
  • Structured Output Format: The prompt specifies a precise markdown output format, prioritizing the most critical information for an analyst. The report always begins with the input query and the source links (emphasized by the speaker as vital for analyst verification against potential LLM hallucination). This is followed by a dedicated section for all identified investigative artifacts, then key insights derived from the scraped data, and finally, next steps or example queries for continued investigation.

Robin supports integration with various LLM providers, including OpenAI, Google Gemini, and Anthropic Claude. For users preferring to run models locally, it offers support through Ollama, enhancing privacy and control over the inference process. The tool is available with both a CLI and a Web UI, catering to different user preferences and operational environments. The output reports are generated in markdown format, which not only ensures readability but also facilitates easy ingestion by other LLMs or automated systems for further analysis.

Demo / Proof of Concept

▶ Watch: LLM refines user queries for better search results (7:00)

Apurv Singh Gautam provided a video demonstration of Robin, showcasing both its Command Line Interface (CLI) and Graphical User Interface (UI). The demo illustrated the tool's end-to-end functionality, from inputting a query to generating a comprehensive investigative report.

In the CLI demonstration, the speaker showed how easily Robin could be invoked: robin <query> -t <threads>. For instance, a query like "ransomware" would initiate the process. The tool then displayed its progress, indicating the query refinement, link discovery, filtering, and scraping stages. The entire process, from query input to report generation, was observed to take approximately 30 to 45 seconds, a significant time saving compared to manual methods.

The UI demonstration, described as "far more intuitive," presented a user-friendly interface where an analyst could simply type a query (e.g., related to a specific ransomware group or cybercrime topic) and click "run." The UI visually tracked the workflow, showing that it initially found 100+ links, which were then intelligently filtered down to 15-20 relevant links before scraping commenced.

The most critical part of the demonstration was the generated investigative report, which was displayed in detail. Key elements of the report included:

  • Input Query: Clearly stating the original search term.
  • Source Links: A list of the actual .onion URLs from which the information was scraped. The speaker stressed the importance of these links, allowing analysts to independently verify the LLM's findings and guard against potential hallucinations.
  • Investigative Artifacts: This section, highlighted as the most valuable, listed specific indicators extracted from the scraped content. Examples shown included various ransomware names (e.g., BlackBasta ransomware) and cryptocurrency addresses.
  • Key Insights: A summarized, contextualized understanding of the scraped data, providing a high-level overview of the findings.
  • Next Steps / Example Queries: Robin intelligently suggested follow-up queries that analysts could use to further refine their investigation. For example, if the report mentioned "BlackBasta ransomware," it might suggest "BlackBasta ransomware" as a new query to dive deeper into that specific threat actor.

The report was generated in markdown format, making it easily readable and adaptable for integration into other systems or for further processing by additional LLMs. This demonstration effectively validated Robin's ability to automate and streamline complex dark web OSINT tasks, delivering actionable intelligence in a structured and timely manner.

Defensive Implications

▶ Watch: LLM filters 200+ search results to top 20 (8:00)

Robin presents significant defensive implications for organizations and cybersecurity professionals, empowering them to proactively monitor the dark web and enhance their threat intelligence capabilities. By automating the arduous process of dark web OSINT, defenders can:

  1. Proactive Threat Monitoring: Organizations can use Robin to continuously scan dark web forums and marketplaces for mentions of their brand, intellectual property, or critical infrastructure. This allows for early detection of potential threats, data breaches, or discussions related to planned attacks targeting their assets.
  2. Ransomware Intelligence: With the rise of ransomware, tracking specific ransomware groups, their tactics, techniques, and procedures (TTPs), and their negotiation channels on the dark web is crucial. Robin can quickly identify ransomware names, crypto addresses, and associated threat actor aliases, providing vital intelligence for incident response and mitigation.
  3. Data Breach Detection and Verification: If an organization suspects a data breach or hears rumors of its data being sold, Robin can be deployed to search for mentions of compromised credentials, PII, or corporate data. The generated reports, complete with source links, enable rapid verification and assessment of the breach's scope.
  4. Threat Actor Tracking: Security teams can leverage Robin to track specific threat actors or groups, monitoring their activities, communications, and evolving capabilities. The tool's ability to extract threat actor aliases and related artifacts aids in building comprehensive profiles of adversaries.
  5. Vulnerability and Exploit Intelligence: The dark web is often a marketplace for zero-day exploits and vulnerabilities. Robin can help identify discussions around new exploits or the sale of access to vulnerable systems, allowing defenders to patch or implement preventative measures before widespread exploitation.
  6. Enhanced Analyst Efficiency: By dramatically reducing the manual effort involved in dark web OSINT, Robin frees up valuable analyst time. Instead of spending hours collecting and sifting through data, analysts can focus on higher-value tasks such as interpreting intelligence, correlating findings with internal data, and developing strategic defensive postures. The structured markdown reports and suggested next steps further expedite the analysis process.
  7. Improved Reporting and Communication: The standardized, artifact-rich reports generated by Robin ensure consistent and clear communication of intelligence findings within security teams and to leadership, facilitating quicker decision-making. The inclusion of source links also builds trust and allows for independent validation of AI-generated insights, mitigating the risk of LLM hallucinations.

In essence, Robin transforms dark web OSINT from a labor-intensive, reactive process into a more automated, proactive, and efficient component of a robust threat intelligence program, significantly strengthening an organization's defensive capabilities.

Key Takeaways

  • Integrated OSINT Workflow: Robin unifies the entire dark web intelligence gathering process—from searching and filtering to scraping and analysis—into a single, efficient tool, eliminating the need for fragmented, multi-tool workflows.
  • AI-Driven Automation: Large Language Models (LLMs) are strategically applied for intelligent query refinement, precise filtering of relevant links (reducing 200+ to top 20), and comprehensive report generation, significantly automating traditionally manual tasks.
  • Actionable Investigative Reports: The tool generates detailed markdown reports that prioritize investigative artifacts (e.g., crypto addresses, ransomware names, PII) and provide contextual insights, along with suggested next steps for continued analysis.
  • Analyst Verification and Trust: Robin provides source links in its reports, allowing analysts to verify LLM-generated findings and mitigate the risks of hallucination, fostering trust in the automated intelligence.
  • Enhanced Efficiency and Proactivity: By automating dark web reconnaissance, Robin drastically reduces the time and effort for threat intelligence analysts, enabling them to focus on interpreting threats and proactively bolstering defensive strategies.
  • Flexible LLM Support: The tool supports major LLM providers (OpenAI, Gemini, Claude) and local models via Ollama, offering adaptability for diverse user environments and security preferences.

About the Speaker(s)

Apurv Singh Gautam is a Senior Threat Research Analyst at Cyber, where his work focuses extensively on cybercrime and threat intelligence. A graduate of Georgia Tech, Apurv brings a strong academic background to his practical work in cybersecurity. He has made significant contributions to the field, including his involvement in the SANS Cyber Crime Intelligence course, which he mentioned during his talk. His expertise lies in understanding and analyzing the evolving landscape of cyber threats, particularly those originating from or leveraging the dark web. Apurv's dedication to improving the efficiency of threat intelligence is evident in his development of tools like Robin, aimed at empowering analysts with advanced, automated capabilities.

Reviews

Dr. Zero (Offensive Security Researcher) — SOLID

Robin is a competent tooling talk that solves a real analyst pain point — consolidating fragmented dark web OSINT workflows into a single LLM-orchestrated pipeline. The work is genuine, the demo is functional, and the prompt engineering decisions (index-based filtering to suppress hallucinations) show the speaker actually built and iterated on this thing. Nothing here will redefine the field, but it's honest practitioner work presented clearly.

Heather Calloway (CISO) — SOLID

Robin is a competent analyst productivity tool that consolidates a genuinely fragmented dark web OSINT workflow into something usable. The talk delivers on its narrow promise but stops short of anything a CISO or security program leader would act on — it's a practitioner demo, not a strategic intelligence brief.

→ Top-rated talks at Recon Village @ DEF CON 33

All talks from Recon Village @ DEF CON 33