Operational Security (OPSEC)
Definition
The set of practices a threat actor uses to prevent adversaries from identifying them or their infrastructure. In dark web investigations, OPSEC failures by administrators, such as reusing usernames, exposing real IP addresses through misconfigured servers, or posting personal information in clearnet forums, are the most common route to attribution.
- Goal
- Prevent adversaries from identifying an actor or their infrastructure
- Common failures
- Username reuse, exposed real IPs, clearnet personal posts
- Applies to
- Dark web vendors, forum administrators, cybercriminal groups
- Investigative value
- Single OPSEC lapse can unravel years of anonymity
Common questions
Why does username reuse compromise a threat actor who is otherwise careful?+
A distinctive handle used on a dark web marketplace and also on an old clearnet forum, gaming account, or email address can be cross-referenced through OSINT tools, linking the anonymous persona to a real identity even when the current infrastructure is well hidden.
What is a common OPSEC mistake specific to server administrators?+
Misconfiguring a hidden service so that it briefly leaks its real IP address, for example through a debug page, an unproxied error message, or a service left listening on both a Tor and clearnet interface, is one of the most cited routes to deanonymising dark web infrastructure.
Related terms
- Blockchain Analytics
- The use of tools such as Chainalysis, Elliptic, or CipherTrace to trace cryptocurrency fund flows across a public ledger. Because most public...
- Bulletproof Hosting
- Hosting providers, typically in jurisdictions with weak law enforcement cooperation, that explicitly or implicitly ignore takedown requests and abuse complaints. Dark web...
- DC-Cam
- Documentation Center of Cambodia. NGO established in 1995 as a field office of Yale University's Cambodian Genocide Program and became independent in...
- Escrow Wallet
- A cryptocurrency address controlled by the marketplace that holds a buyer's payment until the buyer confirms receipt. Escrow wallets create an auditable...
- EULEX
- European Union Rule of Law Mission in Kosovo. Deployed in 2008; included a forensic component responsible for assisting Kosovo authorities with missing-persons...
- Evidence Contamination by Political Process
- The compromise of forensic evidence through interference by parties with a stake in the investigation's outcome: selective disclosure, substitution of remains, access...
- FAFG
- Fundacion de Antropologia Forense de Guatemala. National forensic anthropology organisation established 1992, carrying out exhumations related to Guatemala's internal armed conflict (1960-1996);...
- Mutual Legal Assistance Treaty (MLAT)
- A bilateral or multilateral treaty under which signatory states agree to assist each other in gathering evidence for criminal investigations. MLATs define...
- OHCHR Field Manual
- The UN Office of the High Commissioner for Human Rights Field Manual on Human Rights Monitoring. Provides operational guidance for human rights...
- Onion Service
- A Tor-based server reachable only through the Tor network via a .onion address derived from the service's public key. The routing protocol...
Explained in these topics
- Dark Web Marketplaces and Criminal Infrastructure
- Working in Conflict and Politically Sensitive ContextsThe set of practices designed to prevent adversaries from obtaining information about team plans, sources, locations, or findings before those findings are sec...