This guide consolidates dark web investigation, favicon fingerprinting, and origin IP discovery techniques into a single reference.
- OnionScan GitHub - Primary source code and documentation.
- Vice: OnionScan Review - Overview of functionality and purpose.
- Mascherari Press (June 2016) - Analysis of security flaws and vulnerabilities.
- Forensic Finances - Financial transaction patterns in dark markets.
- FHII Compromise - Freedom Hosting II breach survey.
- Sarah Jamie Lewis Talk - Practical de-anonymization of hidden services.
- OnionScan & Shodan Automation - Automated OSINT pipeline development.
Leveraging favicon hashes to link infrastructure or identify shared backend servers.
- FavFreak (GitHub) - Tool for automated reconnaissance.
- Fav-Up (GitHub) - Favicon hash generator.
- Weaponizing Favicons (Medium) - Advanced reconnaissance pipeline.
- Shodan via Favicon Hash (Video) - Practical walkthrough.
Revealing the true origin IP address of servers hidden behind CDNs (like Cloudflare) or Tor.
- Historical DNS: Analyzing records via SecurityTrails or ViewDNS for pre-protection IP exposure.
- SSL Fingerprinting: Querying Shodan/Censys using certificate hashes to locate origin servers.
- Favicon Tracing: Identifying infrastructure through unique favicon hash matches.
- SECJuice Guide - Comprehensive guide on origin IP discovery.
- Censys / Shodan - Global infrastructure search engines.
⚠️ Ethical Warning: Ensure all investigative activities remain within legal boundaries and authorized scopes. Automated scanning can be intrusive and detectable.