Uploaded March 2026 | Updated September 2026, 2 weeks ago
Archaeologist of the Dark Web - Because Manual Dark Web OSINT is So Last Season
Presenter: Apurv Singh Gautam
Dark Web OSINT and cyber threat intelligence investigations can get overwhelming fast. Investigators deal with endless onion links, unreliable marketplaces, scattered search engines, and constant time pressure. This talk introduces Robin, an AI powered Dark Web OSINT tool built to streamline and speed up your entire investigative workflow.
Robin automatically searches multiple Dark Web search engines, scrapes relevant onion sites, validates results, and uses AI to produce clear, actionable summaries. No more juggling multiple tools or wasting hours checking dead links. In this session, we break down the biggest challenges in Dark Web OSINT, how Robin’s architecture works, and how its scraping and summarization pipeline fits into real world CTI and investigation workflows.
If you work in OSINT, CTI, cyber investigations, threat intelligence, or Dark Web research, this talk gives you a practical tool you can start using immediately and a clearer understanding of how AI can simplify the investigative process.
00:00 Introduction – Robin: AI-Powered Dark Web Investigation Tool
01:53 Agenda – Dark Web OSINT, Existing Tools & Demo
02:37 Why Dark Web Investigation Matters for Threat Intel
04:01 Existing Dark Web OSINT Tools & Their Limitations
05:25 Why Build Robin? Combining Tools with AI
06:14 Introducing Robin – AI-Powered Dark Web OSINT Tool
07:00 Robin Architecture Overview
13:10 Prompt Engineering for Threat Intelligence Analysis
16:21 Investigation Summary Output Structure
18:23 Live Demo – Running Robin via Docker & Web UI
21:36 Search Results and Investigation Output
24:50 Using the Output for Threat Intelligence Reports
26:20 Future Features and Improvements
27:55 Project Credits & Inspiration
29:00 Audience Q&A
Sign Up for WWHF
Register for this year’s Wild West Hackin Fest here:
wildwesthackinfest.com/wild-west-hackin-fest-mile-high-2026
Get access to workshops, labs, and sessions taught by experienced practitioners, all focused on real world defensive and investigative skills.
#OSINT #DarkWeb #ThreatIntelligence #CTI #CyberSecurity #OnionSites #AItools #InvestigationTools #InfoSec #WWHF #CyberThreats
///Black Hills Infosec Socials
Twitter: twitter.com/BHinfoSecurity
Mastodon: https://infosec.exchange/@blackhillsinfosec
LinkedIn: linkedin.com/company/antisyphon-training
Discord: discord.gg/ffzdt3WUDe
///Black Hills Infosec Shirts & Hoodies
spearphish-general-store.myshopify.com/collections/bhis-shirt-collections
///Black Hills Infosec Services
Active SOC: blackhillsinfosec.com/services/active-soc
Penetration Testing: blackhillsinfosec.com/services
Incident Response: blackhillsinfosec.com/services/incident-response
///Backdoors & Breaches - Incident Response Card Game
Backdoors & Breaches: backdoorsandbreaches.com
Play B&B Online: play.backdoorsandbreaches.com
///Antisyphon Training
Pay What You Can: antisyphontraining.com/pay-what-you-can
Live Training: antisyphontraining.com/course-catalog
On Demand Training: antisyphontraining.com/on-demand-course-catalog
Antisyphon Discord: discord.gg/antisyphon
Antisyphon Mastodon: https://infosec.exchange/@Antisy_Training
///Educational Infosec Content
Black Hills Infosec Blogs: blackhillsinfosec.com/blog
Wild West Hackin' Fest YouTube: youtube.com/wildwesthackinfest
Antisyphon Training YouTube: youtube.com/antisyphontraining
Active Countermeasures YouTube: youtube.com/activecountermeasures
Threat Hunter Community Discord: discord.gg/threathunter
Join us at the annual information security conference in Deadwood, SD (in-person and virtually) — Wild West Hackin' Fest: wildwesthackinfest.com
Archaeologist of the Dark Web - Because Manual Dark Web OSINT is So Last Season
Presenter: Apurv Singh Gautam
Dark Web OSINT and cyber threat intelligence investigations can get overwhelming fast. Investigators deal with endless onion links, unreliable marketplaces, scattered search engines, and constant time pressure. This talk introduces Robin, an AI powered Dark Web OSINT tool built to streamline and speed up your entire investigative workflow.
Robin automatically searches multiple Dark Web search engines, scrapes relevant onion sites, validates results, and uses AI to produce clear, actionable summaries. No more juggling multiple tools or wasting hours checking dead links. In this session, we break down the biggest challenges in Dark Web OSINT, how Robin’s architecture works, and how its scraping and summarization pipeline fits into real world CTI and investigation workflows.
If you work in OSINT, CTI, cyber investigations, threat intelligence, or Dark Web research, this talk gives you a practical tool you can start using immediately and a clearer understanding of how AI can simplify the investigative process.
00:00 Introduction – Robin: AI-Powered Dark Web Investigation Tool
01:53 Agenda – Dark Web OSINT, Existing Tools & Demo
02:37 Why Dark Web Investigation Matters for Threat Intel
04:01 Existing Dark Web OSINT Tools & Their Limitations
05:25 Why Build Robin? Combining Tools with AI
06:14 Introducing Robin – AI-Powered Dark Web OSINT Tool
07:00 Robin Architecture Overview
13:10 Prompt Engineering for Threat Intelligence Analysis
16:21 Investigation Summary Output Structure
18:23 Live Demo – Running Robin via Docker & Web UI
21:36 Search Results and Investigation Output
24:50 Using the Output for Threat Intelligence Reports
26:20 Future Features and Improvements
27:55 Project Credits & Inspiration
29:00 Audience Q&A
Sign Up for WWHF
Register for this year’s Wild West Hackin Fest here:
wildwesthackinfest.com/wild-west-hackin-fest-mile-high-2026
Get access to workshops, labs, and sessions taught by experienced practitioners, all focused on real world defensive and investigative skills.
#OSINT #DarkWeb #ThreatIntelligence #CTI #CyberSecurity #OnionSites #AItools #InvestigationTools #InfoSec #WWHF #CyberThreats
///Black Hills Infosec Socials
Twitter: twitter.com/BHinfoSecurity
Mastodon: https://infosec.exchange/@blackhillsinfosec
LinkedIn: linkedin.com/company/antisyphon-training
Discord: discord.gg/ffzdt3WUDe
///Black Hills Infosec Shirts & Hoodies
spearphish-general-store.myshopify.com/collections/bhis-shirt-collections
///Black Hills Infosec Services
Active SOC: blackhillsinfosec.com/services/active-soc
Penetration Testing: blackhillsinfosec.com/services
Incident Response: blackhillsinfosec.com/services/incident-response
///Backdoors & Breaches - Incident Response Card Game
Backdoors & Breaches: backdoorsandbreaches.com
Play B&B Online: play.backdoorsandbreaches.com
///Antisyphon Training
Pay What You Can: antisyphontraining.com/pay-what-you-can
Live Training: antisyphontraining.com/course-catalog
On Demand Training: antisyphontraining.com/on-demand-course-catalog
Antisyphon Discord: discord.gg/antisyphon
Antisyphon Mastodon: https://infosec.exchange/@Antisy_Training
///Educational Infosec Content
Black Hills Infosec Blogs: blackhillsinfosec.com/blog
Wild West Hackin' Fest YouTube: youtube.com/wildwesthackinfest
Antisyphon Training YouTube: youtube.com/antisyphontraining
Active Countermeasures YouTube: youtube.com/activecountermeasures
Threat Hunter Community Discord: discord.gg/threathunter
Join us at the annual information security conference in Deadwood, SD (in-person and virtually) — Wild West Hackin' Fest: wildwesthackinfest.com










![Exfiltrate and Command Network Nodes Like a Ghost! | Momen Eldawakhly | WWHF 2023
🔗 Join us in-person and virtually at our Wild West Hackin Fest: information security conferences — https://wildwesthackinfest.com/
Our role as “red teamers” is to try developing techniques that simulate these activities and to improve organisational security by training defensive security teams to check for every single bit (not literally) of data and also anticipate the locations from which attackers may conduct their operations. The technique discussed in this research only shows the basic mindset that can be developed further with each engagement.
Momen Eldawakhly, also known as CyberGuy, is a senior penetration tester at Samurai Digital Security Ltd and red team engineer with a strong track record in security research and red teaming. He has been recognized by major companies such as Google, Yahoo, Microsoft, Yandex, Redhat, AT&T, Oneplus, SecureBug, Starbucks, Comcast, the United Nations, IBM, Nokia, and Sony for discovering critical and high severity vulnerabilities in their assets. Momen is also dedicated to sharing his knowledge with the cybersecurity community, and has given talks and sessions at various conferences and events. Honors: Some of Momen’s notable honors include being featured in conferences such as Black Hat, The Hack Summit, Wild West Hackin’ Fest, IEEE, Hacken, and GDSC. He has also discovered several zero days during his offensive security research, as listed in the publications section of his profile. Certifications: LPT [Master], CPENT ,OSWP, CRTO, CRTP ,eWAPTXv2.
///Black Hills Infosec Socials
Twitter: https://twitter.com/BHinfoSecurity
Mastodon: https://infosec.exchange/@blackhillsinfosec
LinkedIn: https://www.linkedin.com/company/antisyphon-training
Discord: https://discord.gg/ffzdt3WUDe
///Black Hills Infosec Shirts & Hoodies
https://spearphish-general-store.myshopify.com/collections/bhis-shirt-collections
///Black Hills Infosec Services
Active SOC: https://www.blackhillsinfosec.com/services/active-soc/
Penetration Testing: https://www.blackhillsinfosec.com/services/
Incident Response: https://www.blackhillsinfosec.com/services/incident-response/
///Backdoors & Breaches - Incident Response Card Game
Backdoors & Breaches: https://www.backdoorsandbreaches.com/
Play B&B Online: https://play.backdoorsandbreaches.com/
///Antisyphon Training
Pay What You Can: https://www.antisyphontraining.com/pay-what-you-can/
Live Training: https://www.antisyphontraining.com/course-catalog/
On Demand Training: https://www.antisyphontraining.com/on-demand-course-catalog/
Antisyphon Discord: https://discord.gg/antisyphon
Antisyphon Mastodon: https://infosec.exchange/@Antisy_Training
///Educational Infosec Content
Black Hills Infosec Blogs: https://www.blackhillsinfosec.com/blog/
Wild West Hackin Fest YouTube: https://www.youtube.com/wildwesthackinfest
Antisyphon Training YouTube: https://www.youtube.com/antisyphontraining
Active Countermeasures YouTube: https://youtube.com/activecountermeasures
Threat Hunter Community Discord: https://discord.gg/threathunter
Join us at the annual information security conference in Deadwood, SD (in-person and virtually) — Wild West Hackin Fest: https://wildwesthackinfest.com/ Exfiltrate and Command Network Nodes Like a Ghost! | Momen Eldawakhly | WWHF 2023](https://i.ytimg.com/vi/qCMGdzhJ6nY/mqdefault.jpg)