This is a working manual for building dark web threat intelligence with your own hands. Over 109 labs you stand up a real anonymity lab, learn Tor, I2P and Hyphanet (Freenet) from the inside, then write the collection and analysis engines an intelligence workflow actually needs: a crawler with a scope guard, a mirror and clone separator, extractors for markets, forums and leak sites, a persona linkage engine, a change monitor, and a capstone that chains all of them into one decision-ready report.
Everything runs against a watermarked synthetic darknet that ships with the book, so you can be wrong safely. When the range is not enough, four optional labs run your engines over real archived public data: a marketplace slice, a leak-site feed, and a scrubbed corpus of ransomware negotiation transcripts.
What you buildEvery chapter carries the reasoning, the commands, the expected output, and a gate you must pass before moving on. It also names the specific way each chapter can go wrong: accepting poisoned data, missing a bluff, merging two operators into one, crying wolf, and finally overclaiming, which is the only failure no adversary causes. The book is complete on its own. A companion site ships with it so the commands are easier to copy than to type.
Who it is forAnalysts, incident responders, threat intelligence teams, and instructors who need a curriculum that runs. You need Docker, roughly 8 GB of RAM, and comfort in a Linux shell. Budget about 80 hours at intermediate level, or 108 if this is your first time with containers and Python at this depth; every lab carries its own estimate so you can plan a session, a week, or a term.
Nothing here requires touching live criminal infrastructure, and nothing here teaches you to run one. The discipline this book teaches is the one that makes intelligence usable: every claim carries its provenance, every link can be falsified, attribution stops at the operator, and the report says only what the evidence supports.
Volume 1 stands on its own. Volume 2 assumes it.