OSINT Radar
Dark Web OSINT Operational

Onion Scan Tool

github.com

OnionScan is a free and open source tool for investigating the Dark Web.

Free Open Source #Onion Scan Tool #Dark Web OSINT tools #Dark Web OSINT resources #onion #dark #scan #web #capabilities #darknet #discovery
Open tool

Pivot map

You have domain url
You get onion services mentions

Use this map to decide whether Onion Scan Tool accepts the lead you are holding, and what kind of lead it may return for the next step.

Pivot from here

Outputs from Onion Scan Tool can become inputs for the next tool. These are the most relevant follow-on pivots in the library.

Investigator Use

OnionScan Tool (github.com/s-rah/onionscan) is the primary GitHub repository for the OnionScan project — the open-source Tor hidden service analysis framework developed by security researcher Sarah Jamie Lewis. This is the definitive source for the OnionScan codebase, documentation, issue tracker, and release history.


For OSINT investigators and technical security researchers, this repository is the starting point for deploying OnionScan in an investigation environment. It contains the complete Go source code, installation instructions, configuration options, and usage examples for scanning Tor hidden services for de-anonymization vulnerabilities.


The tool works by connecting to a target onion address through the Tor network and systematically querying it for technical information that may reveal operational security failures. Findings include SSH host key correlations (the same key appearing on surface web servers identifies the hosting infrastructure), Apache/nginx server fingerprints, PHP session IDs, Bitcoin addresses embedded in pages, email addresses in page metadata, and misconfigured directory listings.


OnionScan's correlation database is particularly powerful — the tool can cross-reference discovered artifacts (SSH keys, SSL certificates, Bitcoin addresses) against its database to identify matches with surface web services, effectively providing automatic de-anonymization leads without manual research.


The GitHub repository also contains an extensive report on dark web operational security failures derived from scanning thousands of hidden services, which serves as a reference for the types of mistakes investigators should look for when manually analyzing a dark web target.


Operational and legal considerations: OnionScan must be run through Tor. Scanning systems without authorization may violate computer fraud laws in your jurisdiction. The tool is appropriate for authorized security research, law enforcement investigations with proper legal authority, and CTF/training environments.


Setup requires Go 1.x and Tor. Clone the repository, follow the build instructions in the README, and configure your Tor proxy settings before running scans. Log all scan outputs with timestamps for case documentation.

Before You Pivot

Record Context

Capture the target, search terms, and why this source is relevant before you leave the page.

Preserve Evidence

Archive volatile pages, save screenshots, and keep timestamps for anything that may change.

Corroborate

Treat one tool as a lead source. Confirm important findings with independent sources.

Related tools