open source · self-hosted · MIT

Dark-web intelligence,
structured.

Turn research queries into collection, enrichment, relationship mapping, and export — in one workflow.

VoidAccess automates dark web OSINT investigations end to end — scraping Tor, clearnet sources, and paste sites, then extracting indicators and building a structured intelligence graph without a subscription or vendor lock-in.

void@tor · ~/voidaccess● live
VoidAccess terminal output showing the 13-step investigation pipeline
$pip install voidaccess

Python 3.10+ · local CLI or Docker Compose

01 / the alternative

Enterprise intel pricing.
Open-source control.

VoidAccess is a free, self-hosted alternative to commercial dark-web intelligence platforms.

PlatformModelDeployment
Recorded FutureEnterprise quoteManaged platform
DarkOwlCustom quoteManaged platform
FlareCustom quoteManaged platform
02 / how it works

From query to
intelligence graph.

Read full architecture ↗

Every VoidAccess investigation runs the same dark web scraping and clearnet investigation pipeline — from a natural language query to an analyst-ready report, fully automated and self-hosted on your own infrastructure.

  1. 01Refinequery
  2. 02CollectTor + open web
  3. 03Filtersignal
  4. 04Enrichthreat intel
  5. 05Discoverlinked pages
  6. 06Extractentities
  7. 07Maprelationships
  8. 08Exportanalyst-ready

13 steps under the hood · parallel collection · cache-aware enrichment · structured exports

03 / what it extracts

Find the signal
inside the noise.

Regex, NER, and optional LLM analysis surface indicators and identity context.

Whether you're running a dark web investigation, a clearnet OSINT sweep, or both together, VoidAccess extracts the indicators that matter — cross-referenced against real threat intelligence sources.

01

Network indicators

IPv4 · IPv6 · domains · URLs · .onion · PGP keys

02

File indicators

MD5 · SHA-1 · SHA-256 · malware families

03

Cryptocurrency

Bitcoin · Ethereum · Monero · Litecoin · Zcash · Solana

04

Identity & actors

Handles · people · organizations · ransomware groups

05

Credentials

Cloud keys · tokens · JWTs · API keys · stealer logs

06

Detection content

YARA · Nuclei · Snort · Suricata indicators

08 enrichment layersThreat feedsIP + domain contextFile + identity contextBlockchainOpen-web collection
04 / see it in action

Real investigations.
Real output.

Follow the research trail from a live question to structured intelligence.

05 / quick start

Install once.
Investigate locally.

Run the CLI on your machine or use the full Docker Compose stack. Configure your provider, then start with a query.

Open the README ↗
quick-start.sh
# install
$ pip install voidaccess

# configure your provider and keys
$ voidaccess configure

# run your first investigation
$ voidaccess investigate "LockBit ransomware" \
    --no-llm --no-tor --depth shallow

✓ investigation queued
06 / built for investigation

Built for dark web and clearnet OSINT

VoidAccess is built for security researchers, SOC analysts, and threat intelligence teams who need dark web OSINT and clearnet investigation in one tool. It replaces manual dark web scraping workflows with an automated pipeline — Tor search, paste site collection, GitHub and GitLab scraping, and security RSS monitoring — enriched against real threat intelligence feeds and exported in formats analysts already use.