Dark-web intelligence,
structured.
Turn research queries into collection, enrichment, relationship mapping, and export — in one workflow.
VoidAccess automates dark web OSINT investigations end to end — scraping Tor, clearnet sources, and paste sites, then extracting indicators and building a structured intelligence graph without a subscription or vendor lock-in.

pip install voidaccessPython 3.10+ · local CLI or Docker Compose
Enterprise intel pricing.
Open-source control.
VoidAccess is a free, self-hosted alternative to commercial dark-web intelligence platforms.
| Platform | Model | Deployment |
|---|---|---|
| Recorded Future | Enterprise quote | Managed platform |
| DarkOwl | Custom quote | Managed platform |
| Flare | Custom quote | Managed platform |
| ◉ VoidAccess | $0 software | Self-hosted✓ |
From query to
intelligence graph.
Read full architecture ↗Every VoidAccess investigation runs the same dark web scraping and clearnet investigation pipeline — from a natural language query to an analyst-ready report, fully automated and self-hosted on your own infrastructure.
- 01Refinequery
- 02CollectTor + open web
- 03Filtersignal
- 04Enrichthreat intel
- 05Discoverlinked pages
- 06Extractentities
- 07Maprelationships
- 08Exportanalyst-ready
13 steps under the hood · parallel collection · cache-aware enrichment · structured exports
Find the signal
inside the noise.
Regex, NER, and optional LLM analysis surface indicators and identity context.
Whether you're running a dark web investigation, a clearnet OSINT sweep, or both together, VoidAccess extracts the indicators that matter — cross-referenced against real threat intelligence sources.
Network indicators
IPv4 · IPv6 · domains · URLs · .onion · PGP keys
File indicators
MD5 · SHA-1 · SHA-256 · malware families
Cryptocurrency
Bitcoin · Ethereum · Monero · Litecoin · Zcash · Solana
Identity & actors
Handles · people · organizations · ransomware groups
Credentials
Cloud keys · tokens · JWTs · API keys · stealer logs
Detection content
YARA · Nuclei · Snort · Suricata indicators
Real investigations.
Real output.
Follow the research trail from a live question to structured intelligence.
SITE
Tracking a ransomware ecosystem
Trace actors, infrastructure, and related indicators across the dark web.
Read the investigation ↗INTEL
Following the access broker trail
Move from a marketplace post to entities, enrichment, and relationships.
Read the investigation ↗Install once.
Investigate locally.
Run the CLI on your machine or use the full Docker Compose stack. Configure your provider, then start with a query.
Open the README ↗# install
$ pip install voidaccess
# configure your provider and keys
$ voidaccess configure
# run your first investigation
$ voidaccess investigate "LockBit ransomware" \
--no-llm --no-tor --depth shallow
✓ investigation queuedBuilt for dark web and clearnet OSINT
VoidAccess is built for security researchers, SOC analysts, and threat intelligence teams who need dark web OSINT and clearnet investigation in one tool. It replaces manual dark web scraping workflows with an automated pipeline — Tor search, paste site collection, GitHub and GitLab scraping, and security RSS monitoring — enriched against real threat intelligence feeds and exported in formats analysts already use.