What does dark web monitoring mean in CyberTI?
It means monitoring configured external sources and organizing the resulting signals for analyst review and asset-aware triage.
CyberTI helps analysts monitor relevant external sources, preserve evidence, extract indicators, and determine whether a signal affects protected assets.
External discussions and breach claims are noisy. The cost is not finding one mention; it is deciding whether the mention is credible, relevant, and urgent.
The phrase suggests Tor, and Tor is part of it, but a great deal of what matters to a security team is not hidden at all. Breach claims, access sales, and leaked material circulate on clearnet forums, in Telegram channels, and on paste sites, often before or instead of anywhere darker. Scoping monitoring to onion services alone misses most of the signal.
The useful definition is therefore about access rather than network: places your organisation is discussed that you cannot see from your own logs, and would not find without deliberately going to look.
A mention is cheap. Claims of access to an organisation are frequently resale of someone else's material, exaggeration to attract buyers, or a repackaging of data that has been circulating for years. A monitoring product that alerts on every appearance of your name produces a queue that is mostly wrong, and a queue that is mostly wrong stops being read.
The work is establishing whether a claim is plausible: what is actually being offered, whether the samples match anything real, whether the seller has a history, and whether the same material has appeared before under a different name. That is analyst judgement, and the platform's job is to put the evidence in front of the analyst rather than to guess on their behalf.
The hard engineering problem is not reading a forum once. It is still being able to read it next month. Sources require accounts, sit behind anti-automation checks, move to new domains, go offline for days, and change their page structure without warning. A source list is a claim about intent; what matters is whether each source was actually reachable this week.
This is why collection health is treated as operational state rather than a background detail. A source that has quietly stopped returning results looks exactly like a source with nothing to report, and the difference is the whole value of the monitoring.
Threads are deleted, sellers disappear, forums are seized, and posts are edited after the fact. A finding that consists of a link is worth very little a month later, which is precisely when someone asks you to substantiate it.
Capturing what was published at the time it was seen — the content, the context around it, and the indicators drawn from it — is what makes a finding defensible later, whether the audience is an incident review, a client, or a regulator.
Relevance is decided against an explicit inventory: domains, brands, product names, and terms tied to specific people. A finding is surfaced because it names something you own, not because it sounded serious.
For a provider watching several organisations, that same matching decides routing. Each finding reaches the client it concerns, with its evidence and its triage history attached, and stays out of every other client's view.
It means monitoring configured external sources and organizing the resulting signals for analyst review and asset-aware triage.
CyberTI supports client-scoped assets and workflows so a provider can review relevant findings in the appropriate client context.
See how CyberTI can support your monitoring, triage, and client-scoped operations.
Request access