Pivot map
Pivot from here
Outputs from BlackWeb can become inputs for the next tool. These are the most relevant follow-on pivots in the library.
A global, open, stable, and secure Internet that serves the entire Asia Pacific community
ARIN is a nonprofit, member-based organization that administers IP addresses & ASNs in support of the operation and growth of the Internet.
AbuseIPDB provides IP reputation data and community abuse reports for identifying malicious hosts in network and threat investigations.
AccountKiller provides direct deletion links and step-by-step instructions for removing accounts on hundreds of websites and social platforms.
Lookup email addresses and mailing addresses with reverse email search to identify people and organizations in OSINT investigations.
Addresses.com provides US residential address lookups, reverse phone searches, and people finder tools for locating individuals.
Ancestry search provides access to billions of historical records including census data, vital records, immigration documents, and family trees.
Canada411 is Canada's people directory for finding individuals by name, providing addresses and phone numbers for OSINT investigations.
AccountKiller provides direct deletion links and step-by-step instructions for removing accounts on hundreds of websites and social platforms.
Lookup email addresses and mailing addresses with reverse email search to identify people and organizations in OSINT investigations.
Addresses.com provides US residential address lookups, reverse phone searches, and people finder tools for locating individuals.
Algo VPN automates deployment of a personal WireGuard or IKEv2 VPN server in the cloud for private, secure OPSEC browsing.
Investigator Use
BlackWeb is an open-source blocklist aggregator maintained on GitHub that compiles domains associated with malware distribution, phishing, advertising networks, trackers, and other malicious or unwanted infrastructure. It functions as a curated, machine-readable threat feed intended for use in DNS filtering, firewall rules, and network security monitoring.
For OSINT investigators and threat intelligence analysts, BlackWeb provides a consolidated reference for identifying domains that have been flagged by the security community as malicious or high-risk. When investigating a phishing campaign, malware distribution network, or suspicious infrastructure, cross-referencing observed domains against the BlackWeb lists can quickly establish whether a domain is already known to the community.
The blocklist is compiled from numerous upstream sources including community threat feeds, DNS-based blocklists, and manually curated entries. This multi-source aggregation means it tends to have broader coverage than any single upstream feed, though it also inherits the false positive rates of its source data.
Investigative applications include: validating whether domains found in phishing emails or malware samples are recognized as malicious, incorporating the blocklist into a network monitoring setup to flag traffic to known bad domains, and using the list as a negative lookup — domains NOT on the list may warrant further manual investigation.
For infrastructure analysis, analysts can search the BlackWeb repository for specific domains or patterns to determine if an observed indicator has been previously documented. The GitHub hosting also means the full commit history is available, allowing investigators to determine approximately when a specific domain was first added to the list.
Limitations: BlackWeb is a community-maintained project and is not exhaustive. Novel phishing infrastructure and zero-day malware domains will not appear until reported and incorporated. The list also contains domains from multiple risk categories that may not all be relevant to a specific investigation. Always verify individual domain status with additional tools (VirusTotal, URLScan, Passive DNS) before drawing conclusions.
Document which version or commit hash of the list was used when referencing it in investigation reports.
Before You Pivot
Capture the target, search terms, and why this source is relevant before you leave the page.
Archive volatile pages, save screenshots, and keep timestamps for anything that may change.
Treat one tool as a lead source. Confirm important findings with independent sources.
Related tools
Ahmia indexes Tor hidden services, enabling investigators to search .onion sites by keyword without the Tor browser.
IACA Dark Web Tools is a law enforcement-oriented collection of resources for searching Tor hidden services and dark web content.
Onioff inspects .onion URLs to verify availability, extract page metadata, and map Tor hidden service content for dark web OSINT.
Find the best onion links list here. Working onion links for 2025 with the best dark web links to explore. All working and updated.
OnionScan investigates dark web sites for misconfigurations, operator errors, and links to clearnet infrastructure revealing real identities.
OnionScan is a free and open source tool for investigating the Dark Web.