RAVEN

Conversational Threat Intelligence

RAVEN listens to the dark. It returns what matters.

7
Subsystems
8
Intel Sources
6
Dark Web Sources
174
Tests
View Documentation GitHub

Intelligence Through Conversation

RAVEN doesn't just aggregate feeds. It understands natural language queries, fuses intelligence from 8 API sources and 6 dark web sources, deduplicates and enriches context, and delivers results through a conversational terminal interface. Ask it anything. It knows where to look.

01

PARSER

NATURAL LANGUAGE QUERY

Interprets operator questions in natural language. 10 query intents — from breach lookups and IOC enrichment to threat actor profiling and dark web monitoring. No rigid syntax. Just ask.

02

INTEL

8 API SOURCES

Shodan, Censys, VirusTotal, OTX, GreyNoise, AbuseIPDB, URLhaus, and Pulsedive. Structured threat intelligence from the surface web's best feeds, queried in parallel and correlated automatically.

03

DARK

6 DARK WEB SOURCES

Tor hidden services, paste sites, breach databases, dark web forums, ransomware leak sites, and marketplace monitoring. UNLEASHED-gated. Passive, dry run, or live Tor scraping.

04

ORCHESTRATOR

FUSION & DEDUPLICATION

Merges results from INTEL and DARK subsystems. Deduplicates findings, enriches context, scores confidence, and builds a unified intelligence picture from disparate sources.

05

TUI

CONVERSATIONAL TERMINAL

Rich terminal interface for interactive threat intelligence sessions. Conversational flow — ask follow-up questions, drill into results, pivot across indicators. History and session persistence.

06

EXPORT

ORION / IDRIS / NEMESIS / SIEM

Feeds intelligence directly into ORION for reconnaissance, IDRIS for governance discovery, NEMESIS for reasoning validation, or any SIEM via structured JSON and STIX/TAXII export.

07

WHISPER

CONTINUOUS MONITORING

Background watchdog. 6 alert types — new breaches, credential leaks, dark web mentions, IOC changes, threat actor activity, and infrastructure shifts. Runs silently until something matters.

UNLEASHED Gate

Cryptographic override. Private key controlled. One operator. Founder's machine only.

Standard

Passive API queries only. Surface web intelligence from 8 structured sources. No dark web access. No Tor traffic. No detection risk.

Dry Run

Simulates dark web collection. Shows what sources would be queried, what data would be retrieved. Ed25519 required. No Tor connections made.

Live

Active dark web intelligence. Tor-routed scraping across 6 dark web sources. Real connections to hidden services. Full DARK subsystem engaged.

THIS TOOL IS FOR AUTHORISED SECURITY TESTING ONLY. EVERY EXECUTION IS SIGNED AND LOGGED.

Security Distros & Package Managers

Kali Linux
.deb package
Parrot OS
.deb package
BlackArch
PKGBUILD
PyPI
pip install
Docker
docker-compose
7
Subsystems
174
Tests
26
Tools in Suite
47,747
Ecosystem Tests

A Conversation With the Dark Web.

7 subsystems. 8 intel sources. 6 dark web sources. Conversational interface. Ask anything. RAVEN knows where to look.