Intel

◈ IP INTEL geo, ASN, ISP, VPN flags — any target ◈ CARD CHECK luhn + BIN issuer intelligence ◈ MAG-LAB browser magstripe studio — ISO 7811 encode, read, batch issue (closed-loop only) ◈ MAIL FORENSICS true origin, relay delays, spoof flags, .eml import ◈ IMAGE FORENSICS EXIF, GPS, ELA, edit detection ◈ PHONE LOOKUP carrier, line type, region, timezone — any number ◈ USERNAME SLEUTH find one handle across 12+ platforms ◈ DOMAIN RECON RDAP whois, DNS, nameservers, subdomains

Operate

◈ SMS RENTAL 30-min numbers, refundable ◈ PROXY LAB residential egress, geo builder ◈ STEGO LAB hide words in pictures ◈ BURNER MAIL receive-only mailboxes, countdown

Hunt

◈ TRACK FILE opens report back: IP, city, ISP ◈ CANARY TRAPS links, pixels & honeytokens — instant alerts ◈ DEAD-DROP burn-after-read encrypted notes ◈ SCREENSHOT page capture or rendered-text fallback ◈ FRAUD-SCORE composite IP + email + BIN risk 0-100 ◈ FREE TOOLS DNS, headers, JWT, hasher ◈ PHONE LOOKUP osint: carrier + line type + region ◈ USERNAME SLEUTH osint: handle across platforms ◈ DOMAIN RECON osint: RDAP + DNS + subdomains ◈ DMS dead man switch: silence releases pre-written payload dead-drops ◈ HASH-CHAIN Tamper-evident chain-of-custody logs — edits break the chain at the exact link ◈ GHOST-TEXT hide secret messages in invisible characters inside innocent text ◈ CHAFF deterministic throwaway personas — same seed, same identity, zero storage ◈ LEAK-TRACER per-recipient invisible watermarks — leaks name the leaker ◈ TRACEOUT network traceroute with per-hop geo ◈ TRAP-CHAIN breadcrumb tripwires — each fired trap feeds them the next, maps their path

Account

◈ INBOX no-KYC messaging ◈ SIGN UP username + password, 10 seconds, no KYC ◈ API KEYS account, balance, metered keys ◈ PASS everything's free now — no pass needed ◈ AGENT PASSPORT machine-readable badge

CANARY TRAPS

Tripwires for your files, folders, docs and links. When ANYONE touches one — opens the link, loads the pixel, pastes the credential into a checker — you get an instant alert with their IP, city, ISP and device. Nobody trips a canary by accident: that's the point.

New trap
Log in (no KYC) to see your traps.
API: POST /canary (tag, kind, rearm) · GET /api/canary/list (login) · GET /api/canary/hits?token= (login) — full hit log with geo.
EXAMPLE FLOW — catch someone opening your stolen files
  1. you create a trap tagged laptop-backups, type stealth link.
  2. you save the link as RESTORE_THIS.txt inside your backup folder.
  3. months later a thief copies the folder and opens the file out of curiosity.
  4. them the link opens — a blank 404, nothing suspicious — but the tripwire fires.
  5. you your INBOX lights up: laptop-backups hit from 203.0.113.7 — Rotterdam, NL · KPN · Windows Chrome · their timezone.
  6. open /canary → the trap row shows hit count + view hits → full log: time, IP, geo, device, language.
HOW IT WORKS
  1. A trap is a unique URL that belongs to you alone — one trap per hiding place.
  2. Stealth link returns a plain 404 page so the opener suspects nothing; the pixel is a 1×1 image that loads invisibly inside docs and emails.
  3. The credential type gives you a realistic-looking fake AWS key or DB password — attackers who find it run it through a checker, and the check itself is the tripwire.
  4. Every hit logs IP, city/region/country, ISP, device, language, referrer — and pings your site INBOX instantly.
  5. Leave rearm OFF for one-shot traps (the trap flips to TRIGGERED), ON when you want to keep counting hits silently.
JARGON — hover any chip:
tripwire honeytoken rearm pixel
FOR AGENTS ?
GET /api/canary/list · GET /api/canary/hits?token=
curl "https://dark0rbits.thetempleofdoom.com/api/canary/hits?token=AbC123" -H "Cookie: dark0rbits_tok=…"Hits include ts, ip, ua, lang, ref. Create traps with POST /canary (form: tag, kind, rearm). · spec: /openapi.json · catalog: /llms.txt
✦ REACH THE DEV
⚙