Unlock the Secrets of the
DARKWEB
Threat Intelligence and Hands-On Labs · Volume 2
Build · Verify · Collect · Attribute

The commands for every lab in the book, ready to copy and run rather than retype. The book prints these same commands; what lives only there is the reasoning behind them and the judgment each one is teaching.

Nothing here touches live infrastructure. You build the networks, you build the services, and you break them yourself, inside a synthetic range that ships with the labs.

Start the labs Chapter 1 · The Container Lab

How this site works

This is the command half of the book. Each page carries the exact things you type, under the same lab number the book uses, so Lab 3.1 here is Lab 3.1 there. What each step does and why it is built that way is written up in the book.

Five items are not here: Labs 11.8, 12.8, 12.9 and 14.8, and Chapter 15. Those run against real archived data or chain every engine into a final report, and they are covered in the book with their commands.

Go to the labs The books Technical appendix

Chapters

Part I · The Range

Workstation tier · can you touch hidden services without exposing yourself?

01
The Container Lab
Stand up the stack, map what reaches the internet, prove the isolation is structural.
in the book
WS · 4G
02
Verified Access
Leak testing, fail-closed verification, and why a leaked .onion query is worse than a DNS leak.
7 labs
WS · 4G
Part II · Protocol & Services

Workstation tier · understand hidden services by building, breaking, and hardening them

03
Tor From the Inside
Your own directory authorities, relays, and exits. Read your own consensus.
7 labs
WS · 4G
04
Onion Services v3, End to End
Descriptors, blinded keys, the full rendezvous handshake, and why enumeration fails.
7 labs
WS · 4G
05
Breaking and Hardening
Deanonymize a misconfigured service, then make it unbreakable.
7 labs
WS · 8G
06
Beyond Tor: I2P
Garlic routing, unidirectional tunnels, and a distributed netDb instead of nine authorities.
7 labs
WS · 8G
07
The Third Architecture: Hyphanet
Content-addressed storage, friend-to-friend darknet mode, and content you cannot delete.
7 labs
WS · 8G
Part III · Collection

Infrastructure tier · onion services are ephemeral; if you aren't watching, you miss it

08
The Simulated Darknet
Markets, forums, leak sites and paste sites, all real onion services you own.
7 labs
INF · 8G
09
Crawling Hidden Services
No DNS, no certificates, no search engine, and latency that breaks ordinary crawlers.
7 labs
INF · 8G
10
Ephemerality, Mirrors, and Clones
Tell a seizure from an exit scam, and a real service from a phishing copy.
7 labs
INF · 8G
11
Marketplaces and Forums
Escrow, reputation, vouching, and PGP keys as the only durable identity.
7 labs
INF · 8G
Part IV · Attribution and Reporting

Infrastructure tier · turn collection into an intelligence product

12
Leak Sites and Negotiation
Around 220 real transcripts across 23 groups, and a local model that keeps them local.
7 labs
INF · 16G
13
Persona Linkage and OPSEC Failure
Stylometry, timezone inference, key reuse: how operators actually get caught.
7 labs
INF · 8G
14
Detecting Anonymity Networks
The defender's chapter: spot Tor, bridges, and I2P on your own network.
7 labs
INF · 8G
15
Capstone and Reporting
One seeded incident threaded through every tool you built.
in the book
INF · 16G
Reference

Optional setup, kept out of the labs

A
Technical Appendix
WSL2 and Docker setup (moved out of Chapter 1), drive relocation and USB, Git and GitHub, running the site locally, and troubleshooting.
Setup +
reference
B
Lab Commands
Every ./lab command with a one-line description and a copy-ready example, plus a spreadsheet download.
Reference

Where to run it

Option A
Your own machine

Docker Desktop on Windows or macOS, Docker Engine on Linux. Comfortable through Parts I and II.

Option B
A VPS

Always-on Linux. Recommended from Part III, where collection runs continuously and outages are the thing you're measuring.

Check first
lab doctor

Reports your platform, memory, and architecture, then tells you which labs run natively and which want the VPS.

Lab times

Every lab in the book with a time to budget for it, so you can plan a session, a week, or a term. Two columns, because the same lab is not the same work for everyone: read the one that describes you and ignore the other.

IntermediateYou are comfortable in a Linux shell and with Docker, and the darknet tooling and the analytic tradecraft are the new part.
EntryThis is your first real exposure to containers, networking or Python at this depth. You read twice, mistype, and chase errors.
Host (Docker)Your own terminal driving ./lab and the containers.
Workstation + hostAlso puts you inside the lab desktop in the browser.
Host, offlinePure Python against archived data, no containers, so it runs on any machine with Python.
RoundingEvery value is rounded up to the next half hour. Unrounded, the book is about 60 h at intermediate level and 84 h at entry.
Every lab, by chapter
Lab Title Intermediate Entry Where
Chapter 1 · The Container Lab · 6 labs · 4–6 h
1.0Clone the lab repository0.5 h0.5 hHost (Docker)
1.1First light1 h1.5 hWorkstation + host
1.2Anatomy of the stack0.5 h1 hHost (Docker)
1.3The gateway route1 h1 hWorkstation + host
1.4Reset discipline0.5 h1 hHost (Docker)
1.5Image provenance0.5 h1 hHost (Docker)
Chapter 2 · Verified Access · 7 labs · 5.5–6.5 h
2.1The four leak surfaces0.5 h0.5 hWorkstation + host
2.2Watch what actually leaves1 h1 hHost (Docker)
2.3The browser is a fingerprint0.5 h1 hHost (Docker)
2.4Behavioural vs structural: proxychains vs the gateway1 h1 hWorkstation + host
2.5Reaching and hosting onion services1 h1 hHost (Docker)
2.6Keyed onions and their friction1 h1 hHost (Docker)
2.7When the gateway says no0.5 h1 hWorkstation + host
Chapter 3 · Tor From the Inside · 7 labs · 6–7.5 h
3.1The control port as an instrument0.5 h1 hWorkstation + host
3.2The consensus: Tor's shared map1 h1 hWorkstation + host
3.3Guards: your fixed door into the network1 h1 hWorkstation + host
3.4Building a circuit: three hops, layered encryption1 h1.5 hWorkstation + host
3.5Streams: how a connection rides a circuit1 h1 hWorkstation + host
3.6Rendezvous, from the outside in1 h1 hWorkstation + host
3.7New identity and circuit hygiene0.5 h1 hWorkstation + host
Chapter 4 · Onion Services v3 · 7 labs · 6.5–8 h
4.1Anatomy of a v3 address0.5 h1 hWorkstation + host
4.2Publish a service the real way1 h1 hWorkstation + host
4.3The descriptor and the hash ring1 h1 hWorkstation + host
4.4Client authorization, properly1 h1.5 hWorkstation + host
4.5Vanity addresses and what they cost1 h1 hWorkstation + host
4.6How onion services get found1 h1.5 hWorkstation + host
4.7Hardening a service you run1 h1 hWorkstation + host
Chapter 5 · Breaking & Hardening · 7 labs · 6.5–8 h
5.1The adversary model0.5 h1 hHost (Docker)
5.2Correlation, at toy scale1 h1.5 hHost (Docker)
5.3Malicious and colluding relays1 h1 hWorkstation + host
5.4Guard discovery and traffic-shaping1 h1 hWorkstation + host
5.5Application-layer deanonymization1 h1.5 hWorkstation + host
5.6Hardening pass: hunt your own leaks1 h1 hWorkstation + host
5.7A threat model that has weights1 h1 hHost (Docker)
Chapter 6 · Beyond Tor: I2P · 7 labs · 6.5–7.5 h
6.1An I2P router in the lab1 h1 hHost (Docker)
6.2The NetDB and floodfill1 h1.5 hHost (Docker)
6.3Tunnels, unidirectional1 h1 hHost (Docker)
6.4Eepsites: access and host1 h1 hHost (Docker)
6.5I2P's threat model vs Tor's1 h1 hHost (Docker)
6.6Both networks, side by side0.5 h1 hHost (Docker)
6.7A comparison you can defend1 h1 hHost (Docker)
Chapter 7 · Hyphanet · 7 labs · 7–8 h
7.1A node in a friend mesh1 h1.5 hHost (Docker)
7.2Insert, retrieve, and outlive the publisher1 h1.5 hHost (Docker)
7.3Mutable content: SSK, USK, freesites1 h1 hHost (Docker)
7.4Opennet vs darknet1 h1 hHost (Docker)
7.5Deniability and the datastore1 h1 hHost (Docker)
7.6Threat model vs Tor and I2P1 h1 hHost (Docker)
7.7The complete overlay decision1 h1 hHost (Docker)
Chapter 8 · The Simulated Darknet · 7 labs · 6.5–7 h
8.1Why simulate, and the tier shift1 h1 hHost (Docker)
8.2A directory and the seed problem0.5 h1 hHost (Docker)
8.3A market and a forum: services have state1 h1 hHost (Docker)
8.4A leak site: persistence and flicker1 h1 hHost (Docker)
8.5Mirrors, clones, and phishing1 h1 hHost (Docker)
8.6Cross-network links1 h1 hHost (Docker)
8.7Ground truth and the scoring harness1 h1 hHost (Docker)
Chapter 9 · Crawling Hidden Services · 7 labs · 4.5–7 h
9.1The frontier: crawling without an index1 h1 hHost (Docker)
9.2Fetching through Tor: slow, unreliable, and you must be polite0.5 h1 hHost (Docker)
9.3Parsing and link extraction across networks0.5 h1 hHost (Docker)
9.4Sessions and state: getting past the wall0.5 h1 hHost (Docker)
9.5Continuous collection: revisiting a moving target0.5 h1 hHost (Docker)
9.6Storage, provenance, and dedup0.5 h1 hHost (Docker)
9.7Scoring the crawler and closing the loop1 h1 hHost (Docker)
Chapter 10 · Mirrors & Clones · 7 labs · 5–7 h
10.1Where exact hashing fails0.5 h1 hHost (Docker)
10.2Shingling and MinHash: near-duplicates0.5 h1 hHost (Docker)
10.3Structural fingerprinting0.5 h1 hHost (Docker)
10.4Identity without keys: secondary signals1 h1 hHost (Docker)
10.5Clustering: one operator, many addresses1 h1 hHost (Docker)
10.6Mirror vs clone: redundancy vs impersonation0.5 h1 hHost (Docker)
10.7Scoring the detector and closing the loop1 h1 hHost (Docker)
Chapter 11 · Markets & Forums · 8 labs · 4–8 h
11.1The market as a database, and a page store0.5 h1 hHost (Docker)
11.2Structured extraction: pages to records0.5 h1 hHost (Docker)
11.3Anti-crawling: detect, never defeat0.5 h1 hHost (Docker)
11.4Sessions at scale, and the shadow-ban0.5 h1 hHost (Docker)
11.5The vendor and reputation graph0.5 h1 hHost (Docker)
11.6The data is adversarial0.5 h1 hHost (Docker)
11.7Scoring extraction, and closing the loop0.5 h1 hHost (Docker)
11.8Extract a real market slice and graph its vendorsoptional0.5 h1 hHost, offline
Chapter 12 · Leak Sites & Negotiation · 9 labs · 5.5–8 h
12.1The extortion operation as two surfaces0.5 h1 hHost (Docker)
12.2Leak-site victim extraction0.5 h0.5 hHost (Docker)
12.3The victim lifecycle over time0.5 h0.5 hHost (Docker)
12.4Reposted victims and affiliate movement0.5 h0.5 hHost (Docker)
12.5The negotiation channel0.5 h1 hHost (Docker)
12.6The bluff is in the gap0.5 h1 hHost (Docker)
12.7Scoring, operator tells, and the hand-off0.5 h1 hHost (Docker)
12.8Negotiate live, then analyse your own transcriptoptional1.5 h1.5 hHost (Docker)
12.9Analyse the real leak-site channeloptional0.5 h1 hHost, offline
Chapter 13 · Persona Linkage · 7 labs · 3.5–6 h
13.1The linkage problem and the identifier ledger0.5 h1 hHost (Docker)
13.2Hard identifiers and the provenance trap0.5 h1 hHost (Docker)
13.3Stylometry, a soft signal0.5 h0.5 hHost (Docker)
13.4Rhythm, handles, and tactic signatures0.5 h0.5 hHost (Docker)
13.5Fusing the signals into an operator0.5 h1 hHost (Docker)
13.6The adversarial identity0.5 h1 hHost (Docker)
13.7Scoring, calibration, and where linkage stops0.5 h1 hHost (Docker)
Chapter 14 · Detection · 8 labs · 4.5–7.5 h
14.1The monitoring shift and the watchlist0.5 h1 hHost (Docker)
14.2The change feed0.5 h1 hHost (Docker)
14.3Classifying events0.5 h1 hHost (Docker)
14.4Scoring and prioritization0.5 h1 hHost (Docker)
14.5Correlation and dedup0.5 h0.5 hHost (Docker)
14.6Noise, drift, and the flood1 h1 hHost (Docker)
14.7Scoring the detector and the watch loop0.5 h1 hHost (Docker)
14.8Monitor the real leak-site change-feedoptional0.5 h1 hHost, offline
Chapter 15 · Capstone & Reporting · 8 labs · 4.5–6 h
15.1The intelligence product0.5 h0.5 hHost (Docker)
15.2The evidence chain0.5 h0.5 hHost (Docker)
15.3Confidence and calibration0.5 h0.5 hHost (Docker)
15.4Assembling the report0.5 h1 hHost (Docker)
15.5Analytic integrity and the overclaim trap1 h1 hHost (Docker)
15.6What would change this0.5 h1 hHost (Docker)
15.7Scoring the report and the book's close0.5 h1 hHost (Docker)
15.8A visual intelligence packageoptional0.5 h0.5 hHost, offline
All 109 labs80 h108 h

The times cover the keyboard: reading the lab, running it, and reading what came back. They do not cover installing Docker, the host preparation in the Technical Appendix, or reading the chapter away from the machine. Where a first run waits on the wall clock rather than on you, that wait is already in the number: the first image build in Lab 1.1, the I2P router integrating in 6.1, the Hyphanet mesh settling in 7.1.

At entry level the book is 108 hours of lab work, a full three-credit semester of lab time, or a fortnight of evenings for someone working through it alone. At intermediate level it is 80. If you need it shorter, the five optional labs and the deep protocol labs in Chapters 3, 6 and 7 are the ones to cut first; the through-line from Chapter 8 onward is the part that builds into the capstone, and cutting there costs you the argument the book is making.