Skip to content

About

No description, website, or topics provided.

Resources

Security policy

Stars

0 stars

Watchers

0 watching

Forks

ย 
ย 

Latest commit

ย 

History

3 Commits

Folders and files

NameName
Last commit message
Last commit date
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 

Repository files navigation

d4rkw3b banner

๐Ÿง… d4rkw3b

darkweb-exposure-toolkit

Python License Privacy Status Author

A privacy-first, terminal-based personal data exposure monitor.

Check if your information has been leaked, sold, or exposed โ€” without leaving your terminal, without paying a subscription, and without handing your data to another company in the process.


The Problem

When you use other sites to check if your data was breached:

  • ๐Ÿ’ธ You pay
  • ๐Ÿ” You hand another company your information while trying to clean up the first ones
  • ๐ŸŒ Your query leaves your machine and hits their servers

d4rkw3b solves all three. Everything runs locally. Results stay on your device. Nothing phones home.


What It Checks

No passwords required. All checks use publicly indexed breach data โ€” the same approach used by Google One, IntelX, and similar services.

Target Method Stored in .env
Email addresses HIBP breach lookup โœ… Yes
Usernames HIBP + GitHub public code scan โœ… Yes
Phone numbers HIBP breach lookup โœ… Yes
Platform usernames HIBP + paste sites (Discord, Steam, Reddit, Instagram + more) Runtime prompt
Passwords k-anonymity โ€” only 5-char hash prefix transmitted, never your full password Runtime prompt
API tokens & keys GitHub public code exposure scan Runtime prompt

Architecture & Privacy Model

Layer Approach
Breach checks HIBP k-anonymity API โ€” only a 5-char SHA-1 hash prefix is transmitted, never your full password
Paste site checks Clearnet only โ€” breach data surfaces on clearnet fast, no dark web access needed or used
Local cache 24hr breach intelligence cache stored in SQLite on your machine โ€” most searches never hit the network
Offline mode Search local cache with zero network exposure after first run
Dark web crawling Not included by design โ€” public breach intelligence is sufficient and legally clean

Security โ†’ Privacy/OPSEC โ†’ Usability. That is the order of priority in every decision this tool makes.

A note on SHA-1

The password k-anonymity check uses SHA-1 hashing. This is not a security decision โ€” it is a requirement of the HIBP k-anonymity API protocol. Only the first 5 characters of the hash are ever transmitted. Your full password never leaves your machine. usedforsecurity=False is set explicitly in the code to document this intent.


Data Sources โ€” Free Tiers Only

This tool is built entirely on free, public APIs. No hidden costs. No subscriptions required.

All sources included at time of development use free tiers only. If you need deeper intelligence, see the Premium Tools section below.

Source Checks API Key Required
HaveIBeenPwned Email, username, phone โ€” breach history Yes (free at haveibeenpwned.com/API/Key)
LeakCheck Email, username, phone โ€” 7B+ records No (free tier)
BreachDirectory Email, username โ€” passwords and hashes No (free)
Emailrep.io Email โ€” reputation, breach history, social profiles Yes (free at emailrep.io/key)
OSINTLeak Email, username โ€” stealer logs, dark web forums Yes (free starter at osintleak.com)
psbdmp.ws Email, username โ€” paste site dumps No

Platform Coverage

Category Platforms
๐ŸŽฎ Gaming Steam, PlayStation Network, Xbox, Roblox, Twitch
๐Ÿ’ฌ Social Discord, Reddit, Twitter/X, Instagram, TikTok, Facebook, LinkedIn, Snapchat, YouTube, Telegram, Spotify
๐Ÿ‘ฉโ€๐Ÿ’ป Developer GitHub

๐Ÿš€ Quick Start

Prerequisites

  • Python 3.10+
  • Terminal (macOS, Linux, or Windows WSL2)

Installation

macOS / Linux:

git clone https://github.com/commit-issues/darkweb-exposure-toolkit.git
cd darkweb-exposure-toolkit
pip3 install -r requirements.txt --break-system-packages
cp .env.example .env

Windows (PowerShell):

git clone https://github.com/commit-issues/darkweb-exposure-toolkit.git
cd darkweb-exposure-toolkit
pip install -r requirements.txt
copy .env.example .env

Open .env in any text editor and fill in your values.

๐Ÿ“– New to this? See the full step-by-step guide: docs/setup.md

HIBP_API_KEY=your_key_here
GITHUB_TOKEN=your_token_here
EMAILS_TO_CHECK=you@example.com
USERNAMES_TO_CHECK=yourusername
PHONES_TO_CHECK=+12125551234

Run

python3 src/run_all_checks.py

Force a cache refresh before scanning:

python3 src/run_all_checks.py --refresh

๐Ÿ“‚ Project Structure

darkweb-exposure-toolkit/ โ”‚ โ”œโ”€โ”€ .env.example โ† Copy to .env, fill in your keys โ”œโ”€โ”€ .gitignore โ† Protects .env and data/ from commits โ”œโ”€โ”€ requirements.txt โ”œโ”€โ”€ setup.cfg โ† Linter configuration โ”œโ”€โ”€ NOTICE โ† Attribution โ€” required to keep on forks โ”‚ โ”œโ”€โ”€ src/ โ”‚ โ”œโ”€โ”€ run_all_checks.py โ† Main entry point โ”‚ โ”œโ”€โ”€ tui.py โ† Terminal UI, banner, pulse spinner โ”‚ โ”œโ”€โ”€ hibp_check.py โ† HIBP breach + k-anonymity password check โ”‚ โ”œโ”€โ”€ github_search.py โ† GitHub public code exposure scan โ”‚ โ”œโ”€โ”€ platform_check.py โ† Platform username checks (Discord, Steam + more) โ”‚ โ”œโ”€โ”€ breach_scraper.py โ† Multi-source breach intelligence scraper โ”‚ โ”œโ”€โ”€ scheduler.py โ† 24hr cache refresh scheduler โ”‚ โ”œโ”€โ”€ validator.py โ† Input validation and sanitization โ”‚ โ”œโ”€โ”€ notifier.py โ† Console output formatter โ”‚ โ”œโ”€โ”€ db_utils.py โ† Local SQLite operations โ”‚ โ”œโ”€โ”€ init_db.py โ† Database setup โ”‚ โ””โ”€โ”€ verify.py โ† Integrity verification โ”‚ โ””โ”€โ”€ data/ โ† Local results DB (gitignored)


๐Ÿ” Privacy & Safety

  • All results stored locally only in data/exposure.db
  • Your .env file is in .gitignore โ€” it will never be committed
  • Delete data/exposure.db at any time to wipe all local results
  • No telemetry, no analytics, no third-party data collection
  • Passwords use k-anonymity โ€” your full password hash never leaves your machine
  • Tokens and keys are entered at runtime only and never written to disk

๐Ÿ”’ Premium Tools โ€” When You Need More

These tools are used by law enforcement, private investigators, security researchers, and journalists for deeper investigations. They are not included in this tool โ€” no paid services are ever called without your explicit configuration.

Tool Used By Free Tier API Best For
IntelX (intelx.io) Law enforcement, Bellingcat, journalists 10 results/search Paid Dark web indexing, full breach records, historical WHOIS
OSINT Industries 5,000+ law enforcement departments No Paid Real-time social footprint across 1,500+ sources
DeHashed Security researchers, pentesters Basic only Paid Largest breach database โ€” IP, email, username, address
Snusbase Developers, researchers No Paid Fast cleartext passwords, hashes, salts, IPs
LeakCheck Pro OSINT researchers Limited Paid 7B+ records with full credential detail
OSINTLeak Pro Security teams, law enforcement Free starter Paid Stealer logs, continuous monitoring, dark web forums

Example Use Cases

Your Discord got compromised and you want to trace it: โ†’ Start here (free, local, private) โ†’ If you need full credential history: LeakCheck Pro or DeHashed

You're a journalist investigating a public figure: โ†’ IntelX for dark web indexing and historical WHOIS โ†’ OSINT Industries for social footprint across 1,500+ sources

You're a security researcher doing a full OSINT sweep: โ†’ DeHashed + Snusbase for deepest credential coverage

You're a PI or law enforcement: โ†’ OSINT Industries (used by 5,000+ departments worldwide) โ†’ IntelX for dark web and archived content

You just want to check your personal exposure for free: โ†’ This tool. That's what it's for.


๐Ÿ“š Resources & Related Guides

Guide Link
Full setup guide (API keys, step by step) docs/setup.md
GitHub account + SSH setup secure-your-repo
Code audit standards code-audit

โš ๏ธ Legal & Ethical Use

This tool is for personal security awareness only.

โœ… Check your own accounts and credentials โœ… Educational use and learning โœ… Personal OPSEC and exposure monitoring โŒ Do not scan accounts you do not own โŒ Do not use for bulk or automated scanning of others


๐Ÿ›ก๏ธ Security & Quality

All source files pass the full audit stack:

black ยท flake8 ยท pylint 10/10 ยท mypy ยท bandit ยท pip-audit ยท detect-secrets ยท vulture ยท radon

Dependencies are pinned and CVE-free at time of release.


๐Ÿ“œ Attribution & Forks

Original author: SudoCode by SudoChef (commit-issues) Original repo: https://github.com/commit-issues/darkweb-exposure-toolkit Created: April 2025

If you fork or build upon this work, you are required to retain the NOTICE file and original copyright notice in LICENSE per MIT License terms. Authorship is embedded in the source code, database, and signed git history.


๐Ÿ“œ License

MIT โ€” see LICENSE.


Built by SudoCode

Security first. Privacy always.

About

No description, website, or topics provided.

Resources

Security policy

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages