Skip to content

Repository files navigation

πŸ‘» Gengar β€” Dark-Web OSINT Search & Crypto Forensics Platform

Gengar Banner

CI License: MIT Node.js Version Docker Support PRs Welcome Security Policy

A high-performance, dark-web investigation and cryptocurrency intelligence engine.
Queries Ahmia hidden services via Tor SOCKS5, probes live .onion endpoints, extracts crypto wallets with NLP intent classification, and generates tamper-evident on-chain evidence dossiers.

Quick Start β€’ Features β€’ Architecture β€’ Forensics Engine β€’ Roadmap β€’ Contributing


⚑ Why Gengar?

Traditional OSINT tools struggle with the volatility and latency of hidden services. Gengar bridges dark-web content discovery with on-chain blockchain intelligence into a unified, privacy-first platform:

  • Zero Clearnet Leaks: Every query, probe, and screenshot routes strictly through Tor SOCKS5 proxy circuits.
  • Resilient Multi-Tier Search: Combines fast Tor .onion HTTP token negotiation, Tor mirror exit routing, and headless Playwright Chromium sessions with aggressive asset filtering.
  • Automated Crypto Forensics: Instantly maps wallet addresses discovered on .onion pages against OFAC sanctions, ransomware syndicates, and darknet market clusters.
  • Court-Admissible Evidence: Generates cryptographically sealed SHA-256 evidence dossiers with immutable Chain of Custody tracking.

πŸ›οΈ Architecture

                       β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”
                       β”‚                     Gengar Platform                    β”‚
                       β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜
                                                    β”‚
                      β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”΄β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”
                      β–Ό                                                          β–Ό
             [ React Web UI :6700 ]                                    [ Express REST / SSE API ]
       (TailwindCSS β€’ Obsidian Cyberpunk)                          (/api/search, /api/probe, /api/forensics)
                      β”‚                                                          β”‚
                      β”‚                                      β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”΄β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”
                      β–Ό                                      β–Ό                                      β–Ό
           [ Browser Client ]                         [ Prober & Crawler ]                  [ Crypto Forensics ]
                                                             β”‚                                      β”‚
                                                             β–Ό                                      β–Ό
                                                  [ Tor SOCKS5 :9050 ]                  [ Mempool / Blockstream ]
                                                             β”‚                          (Dual Engine + Fallback)
                                             β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”΄β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”                      β”‚
                                             β–Ό                               β–Ό                      β–Ό
                                     [ Ahmia .onion ]                 [ Hidden Service ]      [ Threat Intel DB ]
                                     (Search Engine)                   (.onion Targets)      (OFAC, WannaCry, LockBit)

πŸ’» Key Features

  • πŸ‘» Ascii & Cyberpunk UI: Minimalist obsidian interface with violet glow telemetry, zero heavy image dependencies, and responsive live stats.
  • πŸ“‘ Dynamic Live Prober: Live HTTP status code inspection, millisecond latency measurement, and HTML page title resolution for .onion services.
  • πŸ“Έ Headless Visual Snapshots: Automated screenshot capture of alive .onion sites via Playwright Chromium over Tor, with FIFO disk quota management (GENGAR_SCREENSHOT_QUOTA).
  • 🧠 Recursive NLP Blockchain Scraper: Crawls internal .onion subpages to identify crypto wallets (BTC, ETH, XMR, LTC) and classifies intent using weighted context NLP:
  • πŸ”‘ Federated PGP & WKD Intelligence Hub: RFC 4880 OpenPGP parsing with cross-onion entity linking, federated keyserver queries across Ubuntu SKS & Hagrid (keys.openpgp.org), IETF Web Key Directory (WKD) domain verification, and Keybase Social OSINT extraction (linking darknet keys to clearnet GitHub, Twitter/X, and Reddit profiles).
  • πŸ•ΈοΈ Interactive Entity Network Graph: 60 FPS force-directed canvas graph mapping multi-hop transaction flows, co-spent wallet clusters, peeling chains, mixer signatures, PGP identities, and OFAC threat actors with an interactive inspector drawer.
  • βš–οΈ Court-Ready PDF & STIX 2.1 Export: Federal Rules of Evidence (FRE 902(14)) self-authenticating digital evidence reports with print-to-PDF pagination, Chain of Custody audit trails, cryptographic SHA-256 integrity seals, and OASIS STIX 2.1 JSON bundles for SIEM/MISP/OpenCTI ingestion.
  • πŸ”„ Tor Circuit Cycling & Identity Rotation: On-demand Tor ControlPort SIGNAL NEWNYM combined with RFC 1928 SOCKS5 stream isolation (IsolateSOCKSAuth), providing instant exit IP rotation, zero-cooldown circuit switching, and automated background anti-blocking intervals.
  • 🌐 Multi-Chain Forensics (EVM & TRON USDT): Cross-chain intelligence covering Bitcoin UTXO flows, Ethereum / EVM account execution (smart contracts, Tornado Cash mixers, Lazarus Group heists), and TRON TRC-20 high-volume stablecoin laundering and OTC gateways.
  • πŸ”’ API Key Protection: Optional Bearer token authorization (GENGAR_API_KEY) for secure remote deployments while keeping Docker healthchecks open.

🐳 Quick Start with Docker Compose (Recommended)

Get the complete stack running in a single command β€” includes containerized Tor SOCKS5 proxy, Playwright Chromium, Express API, and the React UI:

# 1. Clone the repository
git clone https://github.com/spideydotjs/gengar.git
cd gengar

# 2. Spin up containers
docker compose up -d

Open http://localhost:6700 in your browser!

Useful Docker Commands

# View live application logs
docker compose logs -f

# Check container health status
docker compose ps

# Stop and remove containers
docker compose down

πŸ› οΈ Manual / Local Setup (Without Docker)

Prerequisites

Requirement Version / Specification
Node.js >= 20.0.0
Tor Daemon Running on 127.0.0.1:9050 (SOCKS5)
# Start Tor locally (Ubuntu / Debian)
sudo apt install tor && sudo systemctl start tor

# Start Tor locally (macOS)
brew install tor && brew services start tor

# Verify SOCKS5 proxy is listening
curl --socks5-hostname 127.0.0.1:9050 https://check.torproject.org/api/ip

Installation

# Install root dependencies
npm install

# (Optional) Install client dependencies if modifying the frontend
cd client && npm install && cd ..

Run Gengar

# Start backend and serve pre-built React UI
npm start

# Development mode with hot-reloading backend
npm run dev

# Run unit tests
npm test

πŸ•΅οΈβ€β™‚οΈ Crypto Forensics & Threat Intelligence

Available directly within the Web UI dashboard or programmatically via /api/forensics/*:

  • Transaction Ledger Tracking: Real-time UTXO, inputs/outputs, fee rates, and transfer directions powered by dual Mempool & Blockstream engines.
  • Criminal Threat Correlation: Cross-references addresses against verified threat actors:
    • Ransomware: WannaCry, LockBit 3.0, BlackCat/ALPHV, DarkSide/Colonial Pipeline
    • Darknet Markets: Silk Road (FBI seized), Hydra Market (BKA seized), AlphaBay, Garantex
    • Mixers & Tumblers: Blender.io (OFAC SDN), ChipMixer (DoJ/Europol seized), Tornado Cash
    • Regulated Exchanges: Binance, Kraken, Coinbase (KYC / Subpoena preservation targets)
  • Darknet Heuristics: Automated detection of money-laundering peeling chains and CoinJoin mixer signatures.
  • Tamper-Evident Evidence Vault: Generates legal Chain of Custody records and cryptographically sealed SHA-256 evidence dossiers (data/evidence/CASE-YYYY-XXXX.json) with immutable versioned snapshots.

🌐 API Reference

Health & Tor Status

  • GET /api/health β€” Service health check & active proxy status.
  • GET /api/tor-status β€” Verifies Tor circuit connectivity and exit node IP.
  • GET /api/tor/circuit/status β€” Get active circuit ID, exit IP, control port status, and rotation history.
  • POST /api/tor/circuit/cycle β€” Cycle Tor identity via SIGNAL NEWNYM and SOCKS5 stream isolation.
  • POST /api/tor/circuit/auto-cycle β€” Configure periodic automated background circuit rotation interval.

Search & Prober

  • GET /api/search?q=<query>&probe=true β€” Search Ahmia and optionally probe live hidden services.
  • GET /api/search/stream?q=<query> β€” Server-Sent Events (SSE) stream providing real-time crawl telemetry.
  • POST /api/probe β€” Probe specific .onion URLs for status, title, and latency.

Blockchain OSINT & Forensics

  • POST /api/blockchain-scan β€” Crawl a .onion site recursively for cryptocurrency wallets.
  • GET /api/blockchain-scan/stream?url=<onionUrl> β€” Live SSE stream of discovered wallets and NLP classifications.
  • POST /api/forensics/track β€” Run on-chain ledger analysis, heuristic clustering, and threat correlation.
  • GET /api/forensics/cases β€” List all sealed evidence dossiers in the vault.
  • GET /api/forensics/case/:id β€” Get full sealed case record by case ID.
  • POST /api/forensics/case/note β€” Append examiner notes to a case file and re-seal cryptographic hash.
  • GET /api/forensics/case/:id/export/html β€” Render court-ready FRE Rule 902(14) certified evidence report (?print=true for instant print/PDF).
  • GET /api/forensics/case/:id/export/stix β€” Export case dossier as an OASIS STIX 2.1 compliant CTI JSON bundle.
  • POST /api/forensics/report/html β€” Generate court-ready HTML report dynamically from active session data.
  • POST /api/forensics/report/stix β€” Generate STIX 2.1 JSON bundle dynamically from active session data.

PGP Identity & Fingerprint Intelligence

  • GET /api/pgp/identities β€” List all unique PGP identities discovered across crawl dossiers.
  • GET /api/pgp/identity/:fingerprint β€” Get full identity dossier, cross-onion domain linkage, and wallets for a PGP fingerprint.
  • POST /api/pgp/parse β€” Parse and decode any custom armored PGP public key block on demand.
  • GET /api/pgp/keyserver/:fingerprint β€” Query public keyserver (keys.openpgp.org) over Tor for clearnet email linkage.

Forensic Entity Network Graph

  • GET /api/forensics/graph?address=<addr>&maxTxs=8 β€” Generate multi-hop entity graph for a target address (nodes, edges, threat correlation).
  • GET /api/forensics/graph/global β€” Generate the global darknet ecosystem graph across all stored dossiers and threat entities.

βš™οΈ Environment Variables

Copy .env.example to .env to configure your environment:

Variable Default (Local) Default (Docker) Description
PORT 6700 6700 HTTP listen port
HOST 0.0.0.0 0.0.0.0 Host binding address
TOR_SOCKS socks5h://127.0.0.1:9050 socks5h://tor:9050 Tor SOCKS5 proxy URL
TOR_HOST_PORT 9052 9052 Host port mapped to Tor container
TOR_CONTROL_HOST 127.0.0.1 tor Tor ControlPort hostname
TOR_CONTROL_PORT 9051 9051 Tor ControlPort TCP port for SIGNAL NEWNYM
TOR_CONTROL_PASSWORD (empty) (empty) Optional Tor ControlPort authentication password
GENGAR_API_KEY (empty) (empty) Optional Bearer token for API authentication
GENGAR_EXAMINER OPERATOR_LOCAL OPERATOR_LOCAL Default examiner identifier recorded in evidence
GENGAR_SCREENSHOT_QUOTA 200 200 Maximum screenshots stored before FIFO eviction

πŸ—ΊοΈ Roadmap

  • Multi-tier Ahmia .onion search engine with browser fallback
  • Real-time SSE crawling streams
  • Automated visual screenshot capture over Tor
  • Bitcoin & multi-currency regex wallet extraction
  • NLP context intent classification (Ransom, Escrow, Donation)
  • On-chain UTXO tracing and peeling chain heuristics
  • Cryptographic SHA-256 evidence vault with Chain of Custody
  • OpenPGP RFC 4880 parsing & cross-onion entity correlation
  • Federated PGP & WKD Cross-Reference: Multi-keyserver federation (SKS/HKP, Hagrid/VKS), Keybase social OSINT, and Web Key Directory (WKD) validation over Tor
  • Interactive Visual Entity Graph: Force-directed network visualization of transaction hops, co-spent clusters, and threat actors
  • Court-Ready PDF & STIX 2.1 Reports: Automated certified forensic PDF documentation and SIEM ingestion
  • Tor Circuit Cycling: On-demand NEWNYM signaling and SOCKS5 stream isolation for automated circuit rotation
  • Multi-chain tracking: Support for EVM (Ethereum, Arbitrum) and TRON (USDT TRC-20)
  • Automated AI Case Summarization: Local LLM (Ollama) automated executive briefing & OSINT report generator
  • Target Watchlist & Automated Recurring Triage: Background cron monitoring of .onion threat targets with webhook alerts

🀝 Contributing

Contributions make the open-source community an incredible place to learn, inspire, and create. Any contributions you make are greatly appreciated.

Please review our Contributing Guidelines and Code of Conduct before submitting pull requests.

# Run tests before creating a PR
npm test
npm run build:client

βš–οΈ Legal & Ethical Notice

This software is strictly developed for academic research, lawful open-source intelligence (OSINT), and authorized cybersecurity investigations.

Users are solely responsible for compliance with all local and international laws governing dark-web access and network probing. The developers assume no liability for misuse.


πŸ“„ License

Distributed under the MIT License. See LICENSE for more information.

Built with πŸ‘» by spideydotjs and contributors.

About

πŸ‘» Autonomous Dark-Web OSINT Search Engine & Hidden-Service Prober powered by Ahmia, Tor SOCKS5, and Playwright.

Topics

Resources

Code of conduct

Contributing

Security policy

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages