Threat actor
DarkOwl
Last fetched
DarkOwl is a threat actor tracked in WhisperGraph's MITRE ATT&CK corpus, observed using 0 techniques.
Description
DarkOwl is a cybersecurity company providing tools for dark web intelligence and monitoring. Their platform provides access to a vast database of dark web content, enabling clients to search for leaked credentials, sensitive data, and other details. Its DarkOwl Vision UI has access to a wide range of sources including Tor and Telegram. It also has capabilities for entity-based searches for specific variables like email addresses, IPs, and cryptocurrencies, as well as network-specific filtering to focus on particular darknet platforms, forums or messaging services. Its Dubai-based subsidiary is DarkOwl FZE LLC, which it uses to support intelligence operations by the United Arab Emirates and other governments in the region.
Techniques by tactic
No ATT&CK techniques are recorded for DarkOwl in WhisperGraph.
Attributed infrastructure
None published. WhisperGraph carries no ATTRIBUTED_TO edge to DarkOwl today — this states the absence of a published link, not that DarkOwl has no infrastructure.
References
- https://www.darkowl.com/products/vision-app/
- https://www.darkowl.com/blog-content/darkowl-grows-presence-in-dubai-as-gisec-global-expands/
- https://www.intelligenceonline.com/surveillance--interception/2020/06/17/babel-street-takes-on-dataminr-in-webint-via-ai,109238414-art
- https://www.darkowl.com/press-releases/mst-signs-with-darkowl-to-deliver-critical-darknet-data-to-clients/
- https://magnitt.com/news/ctm360-and-darkowl-announce-partnership-to-enhance-digital-risk-protection-52061
- https://www.darkowl.com/blog-content/darkowl-deepens-international-relationships-at-iss-world-europe/
© The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation.
Related pages
Pivot from DarkOwl into its techniques, tactics and any attributed infrastructure.
Queries
Resolves the slug to this actor, merging every duplicate node sharing the same name.
MATCH (a:ACTOR)
WHERE a.name =~ $pattern OR any(x IN a.aliases WHERE x =~ $pattern)
RETURN a.id AS id, a.name AS name, a.aliases AS aliases, a.description AS description,
a.references AS references, a.campaigns AS campaigns
LIMIT 25Run yourself →Techniques this actor uses, grouped by the tactic each one serves.
MATCH (a:ACTOR {name: $name})-[:USES_TECHNIQUE]->(t:ATTACK_PATTERN)
OPTIONAL MATCH (t)-[:USES_TACTIC]->(tac:ATTACK_PATTERN)
RETURN t.id AS techniqueId, t.name AS techniqueName, tac.id AS tacticId, tac.name AS tacticName
LIMIT 1000Run yourself →Infrastructure publicly attributed to this actor.
MATCH (n)-[:ATTRIBUTED_TO]->(a:ACTOR {name: $name})
RETURN labels(n)[0] AS kind, n.name AS name
LIMIT 25Run yourself →Or query Whisper from your own LLM workflow via the Whisper MCP server.