A high-performance, dark-web investigation and cryptocurrency intelligence engine.
Queries Ahmia hidden services via Tor SOCKS5, probes live .onion endpoints, extracts crypto wallets with NLP intent classification, and generates tamper-evident on-chain evidence dossiers.
Quick Start β’ Features β’ Architecture β’ Forensics Engine β’ Roadmap β’ Contributing
Traditional OSINT tools struggle with the volatility and latency of hidden services. Gengar bridges dark-web content discovery with on-chain blockchain intelligence into a unified, privacy-first platform:
- Zero Clearnet Leaks: Every query, probe, and screenshot routes strictly through Tor SOCKS5 proxy circuits.
- Resilient Multi-Tier Search: Combines fast Tor
.onionHTTP token negotiation, Tor mirror exit routing, and headless Playwright Chromium sessions with aggressive asset filtering. - Automated Crypto Forensics: Instantly maps wallet addresses discovered on
.onionpages against OFAC sanctions, ransomware syndicates, and darknet market clusters. - Court-Admissible Evidence: Generates cryptographically sealed SHA-256 evidence dossiers with immutable Chain of Custody tracking.
ββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ
β Gengar Platform β
ββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ
β
βββββββββββββββββββββββββββββββ΄βββββββββββββββββββββββββββββ
βΌ βΌ
[ React Web UI :6700 ] [ Express REST / SSE API ]
(TailwindCSS β’ Obsidian Cyberpunk) (/api/search, /api/probe, /api/forensics)
β β
β βββββββββββββββββββββ΄βββββββββββββββββββ
βΌ βΌ βΌ
[ Browser Client ] [ Prober & Crawler ] [ Crypto Forensics ]
β β
βΌ βΌ
[ Tor SOCKS5 :9050 ] [ Mempool / Blockstream ]
β (Dual Engine + Fallback)
βββββββββββββββββ΄ββββββββββββββββ β
βΌ βΌ βΌ
[ Ahmia .onion ] [ Hidden Service ] [ Threat Intel DB ]
(Search Engine) (.onion Targets) (OFAC, WannaCry, LockBit)
- π» Ascii & Cyberpunk UI: Minimalist obsidian interface with violet glow telemetry, zero heavy image dependencies, and responsive live stats.
- π‘ Dynamic Live Prober: Live HTTP status code inspection, millisecond latency measurement, and HTML page title resolution for
.onionservices. - πΈ Headless Visual Snapshots: Automated screenshot capture of alive
.onionsites via Playwright Chromium over Tor, with FIFO disk quota management (GENGAR_SCREENSHOT_QUOTA). - π§ Recursive NLP Blockchain Scraper: Crawls internal
.onionsubpages to identify crypto wallets (BTC, ETH, XMR, LTC) and classifies intent using weighted context NLP: - π Federated PGP & WKD Intelligence Hub: RFC 4880 OpenPGP parsing with cross-onion entity linking, federated keyserver queries across Ubuntu SKS & Hagrid (
keys.openpgp.org), IETF Web Key Directory (WKD) domain verification, and Keybase Social OSINT extraction (linking darknet keys to clearnet GitHub, Twitter/X, and Reddit profiles). - πΈοΈ Interactive Entity Network Graph: 60 FPS force-directed canvas graph mapping multi-hop transaction flows, co-spent wallet clusters, peeling chains, mixer signatures, PGP identities, and OFAC threat actors with an interactive inspector drawer.
- βοΈ Court-Ready PDF & STIX 2.1 Export: Federal Rules of Evidence (FRE 902(14)) self-authenticating digital evidence reports with print-to-PDF pagination, Chain of Custody audit trails, cryptographic SHA-256 integrity seals, and OASIS STIX 2.1 JSON bundles for SIEM/MISP/OpenCTI ingestion.
- π Tor Circuit Cycling & Identity Rotation: On-demand Tor ControlPort
SIGNAL NEWNYMcombined with RFC 1928 SOCKS5 stream isolation (IsolateSOCKSAuth), providing instant exit IP rotation, zero-cooldown circuit switching, and automated background anti-blocking intervals. - π Multi-Chain Forensics (EVM & TRON USDT): Cross-chain intelligence covering Bitcoin UTXO flows, Ethereum / EVM account execution (smart contracts, Tornado Cash mixers, Lazarus Group heists), and TRON TRC-20 high-volume stablecoin laundering and OTC gateways.
- π API Key Protection: Optional Bearer token authorization (
GENGAR_API_KEY) for secure remote deployments while keeping Docker healthchecks open.
Get the complete stack running in a single command β includes containerized Tor SOCKS5 proxy, Playwright Chromium, Express API, and the React UI:
# 1. Clone the repository
git clone https://github.com/spideydotjs/gengar.git
cd gengar
# 2. Spin up containers
docker compose up -dOpen http://localhost:6700 in your browser!
# View live application logs
docker compose logs -f
# Check container health status
docker compose ps
# Stop and remove containers
docker compose down| Requirement | Version / Specification |
|---|---|
| Node.js | >= 20.0.0 |
| Tor Daemon | Running on 127.0.0.1:9050 (SOCKS5) |
# Start Tor locally (Ubuntu / Debian)
sudo apt install tor && sudo systemctl start tor
# Start Tor locally (macOS)
brew install tor && brew services start tor
# Verify SOCKS5 proxy is listening
curl --socks5-hostname 127.0.0.1:9050 https://check.torproject.org/api/ip# Install root dependencies
npm install
# (Optional) Install client dependencies if modifying the frontend
cd client && npm install && cd ..# Start backend and serve pre-built React UI
npm start
# Development mode with hot-reloading backend
npm run dev
# Run unit tests
npm testAvailable directly within the Web UI dashboard or programmatically via /api/forensics/*:
- Transaction Ledger Tracking: Real-time UTXO, inputs/outputs, fee rates, and transfer directions powered by dual Mempool & Blockstream engines.
- Criminal Threat Correlation: Cross-references addresses against verified threat actors:
- Ransomware: WannaCry, LockBit 3.0, BlackCat/ALPHV, DarkSide/Colonial Pipeline
- Darknet Markets: Silk Road (FBI seized), Hydra Market (BKA seized), AlphaBay, Garantex
- Mixers & Tumblers: Blender.io (OFAC SDN), ChipMixer (DoJ/Europol seized), Tornado Cash
- Regulated Exchanges: Binance, Kraken, Coinbase (KYC / Subpoena preservation targets)
- Darknet Heuristics: Automated detection of money-laundering peeling chains and CoinJoin mixer signatures.
- Tamper-Evident Evidence Vault: Generates legal Chain of Custody records and cryptographically sealed SHA-256 evidence dossiers (
data/evidence/CASE-YYYY-XXXX.json) with immutable versioned snapshots.
GET /api/healthβ Service health check & active proxy status.GET /api/tor-statusβ Verifies Tor circuit connectivity and exit node IP.GET /api/tor/circuit/statusβ Get active circuit ID, exit IP, control port status, and rotation history.POST /api/tor/circuit/cycleβ Cycle Tor identity via SIGNAL NEWNYM and SOCKS5 stream isolation.POST /api/tor/circuit/auto-cycleβ Configure periodic automated background circuit rotation interval.
GET /api/search?q=<query>&probe=trueβ Search Ahmia and optionally probe live hidden services.GET /api/search/stream?q=<query>β Server-Sent Events (SSE) stream providing real-time crawl telemetry.POST /api/probeβ Probe specific.onionURLs for status, title, and latency.
POST /api/blockchain-scanβ Crawl a.onionsite recursively for cryptocurrency wallets.GET /api/blockchain-scan/stream?url=<onionUrl>β Live SSE stream of discovered wallets and NLP classifications.POST /api/forensics/trackβ Run on-chain ledger analysis, heuristic clustering, and threat correlation.GET /api/forensics/casesβ List all sealed evidence dossiers in the vault.GET /api/forensics/case/:idβ Get full sealed case record by case ID.POST /api/forensics/case/noteβ Append examiner notes to a case file and re-seal cryptographic hash.GET /api/forensics/case/:id/export/htmlβ Render court-ready FRE Rule 902(14) certified evidence report (?print=truefor instant print/PDF).GET /api/forensics/case/:id/export/stixβ Export case dossier as an OASIS STIX 2.1 compliant CTI JSON bundle.POST /api/forensics/report/htmlβ Generate court-ready HTML report dynamically from active session data.POST /api/forensics/report/stixβ Generate STIX 2.1 JSON bundle dynamically from active session data.
GET /api/pgp/identitiesβ List all unique PGP identities discovered across crawl dossiers.GET /api/pgp/identity/:fingerprintβ Get full identity dossier, cross-onion domain linkage, and wallets for a PGP fingerprint.POST /api/pgp/parseβ Parse and decode any custom armored PGP public key block on demand.GET /api/pgp/keyserver/:fingerprintβ Query public keyserver (keys.openpgp.org) over Tor for clearnet email linkage.
GET /api/forensics/graph?address=<addr>&maxTxs=8β Generate multi-hop entity graph for a target address (nodes, edges, threat correlation).GET /api/forensics/graph/globalβ Generate the global darknet ecosystem graph across all stored dossiers and threat entities.
Copy .env.example to .env to configure your environment:
| Variable | Default (Local) | Default (Docker) | Description |
|---|---|---|---|
PORT |
6700 |
6700 |
HTTP listen port |
HOST |
0.0.0.0 |
0.0.0.0 |
Host binding address |
TOR_SOCKS |
socks5h://127.0.0.1:9050 |
socks5h://tor:9050 |
Tor SOCKS5 proxy URL |
TOR_HOST_PORT |
9052 |
9052 |
Host port mapped to Tor container |
TOR_CONTROL_HOST |
127.0.0.1 |
tor |
Tor ControlPort hostname |
TOR_CONTROL_PORT |
9051 |
9051 |
Tor ControlPort TCP port for SIGNAL NEWNYM |
TOR_CONTROL_PASSWORD |
(empty) | (empty) | Optional Tor ControlPort authentication password |
GENGAR_API_KEY |
(empty) | (empty) | Optional Bearer token for API authentication |
GENGAR_EXAMINER |
OPERATOR_LOCAL |
OPERATOR_LOCAL |
Default examiner identifier recorded in evidence |
GENGAR_SCREENSHOT_QUOTA |
200 |
200 |
Maximum screenshots stored before FIFO eviction |
- Multi-tier Ahmia
.onionsearch engine with browser fallback - Real-time SSE crawling streams
- Automated visual screenshot capture over Tor
- Bitcoin & multi-currency regex wallet extraction
- NLP context intent classification (Ransom, Escrow, Donation)
- On-chain UTXO tracing and peeling chain heuristics
- Cryptographic SHA-256 evidence vault with Chain of Custody
- OpenPGP RFC 4880 parsing & cross-onion entity correlation
- Federated PGP & WKD Cross-Reference: Multi-keyserver federation (SKS/HKP, Hagrid/VKS), Keybase social OSINT, and Web Key Directory (WKD) validation over Tor
- Interactive Visual Entity Graph: Force-directed network visualization of transaction hops, co-spent clusters, and threat actors
- Court-Ready PDF & STIX 2.1 Reports: Automated certified forensic PDF documentation and SIEM ingestion
- Tor Circuit Cycling: On-demand NEWNYM signaling and SOCKS5 stream isolation for automated circuit rotation
- Multi-chain tracking: Support for EVM (Ethereum, Arbitrum) and TRON (USDT TRC-20)
- Automated AI Case Summarization: Local LLM (Ollama) automated executive briefing & OSINT report generator
- Target Watchlist & Automated Recurring Triage: Background cron monitoring of .onion threat targets with webhook alerts
Contributions make the open-source community an incredible place to learn, inspire, and create. Any contributions you make are greatly appreciated.
Please review our Contributing Guidelines and Code of Conduct before submitting pull requests.
# Run tests before creating a PR
npm test
npm run build:clientThis software is strictly developed for academic research, lawful open-source intelligence (OSINT), and authorized cybersecurity investigations.
Users are solely responsible for compliance with all local and international laws governing dark-web access and network probing. The developers assume no liability for misuse.
Distributed under the MIT License. See LICENSE for more information.