Overview

Product video
District 4 Labs is a data intelligence company focused on developing next-generation open-source intelligence (OSINT) tools. At the forefront of its offerings is DARKSIDE - one of the world's largest repositories of breached data and other person-of-interest records. Built by investigators for investigators, DARKSIDE empowers professionals to conduct more effective and efficient investigations from tracing threat actors and identifying their online footprints to uncovering the individuals behind online accounts and their hidden connections.
DARKSIDE is an essential asset in the modern intelligence toolkit. DARKSIDE is laser-focused on personally identifiable information (PII) and includes hacked databases, combolists, scraped datasets, compromised public records like voter records or traffic stop records, malware dumps, and more. DARKSIDE contains databases from all over the world from at least the past 20+ years, from Iranian bank breaches to Russian traffic stop records to Honduran voter records and much more. As long as a database contains PII, District 4 Labs will ingest and upload it to DARKSIDE.
We intensively parse every database to ensure the extraction of everything from common identifiers like email addresses, usernames, names, and passwords to less common or sensitive identifiers such as passport numbers, license plate numbers, account creation dates, and much more. Investigators and analysts can search by email address, username/alias, name, password, IP address/CIDR, domain, phone number, and more. The data has been indexed to allow for flexible searching via wildcards, strictness parameters, and even complex searches by multiple identifiers at the same time. By pivoting on newly-found identifiers, users can reveal additional identifiers and accounts associated with a person of interest that were previously unknown. Breached credentials are especially pivotal in the investigation of threat actors because even individuals with strong operational security (OPSEC) make small mistakes like reusing email addresses, usernames, or passwords across different platforms. Historical databases from older accounts, created before a person of interest adopted rigorous OPSEC techniques, can often reveal additional identifiers or patterns in username or password selection. DARKSIDE is an essential asset in the modern intelligence toolkit. DARKSIDE is laser-focused on personally identifiable information (PII) and includes hacked databases, combolists, scraped datasets, compromised public records like voter records or traffic stop records, malware dumps, and more. DARKSIDE contains databases from all over the world from at least the past 20+ years, from Iranian bank breaches to Russian traffic stop records to Honduran voter records and much more. As long as a database contains PII, District 4 Labs will ingest and upload it to DARKSIDE.
We intensively parse every database to ensure the extraction of everything from common identifiers like email addresses, usernames, names, and passwords to less common or sensitive identifiers such as passport numbers, license plate numbers, account creation dates, and much more. Investigators and analysts can search by email address, username/alias, name, password, IP address/CIDR, domain, phone number, and more. The data has been indexed to allow for flexible searching via wildcards, strictness parameters, and even complex searches by multiple identifiers at the same time. By pivoting on newly-found identifiers, users can reveal additional identifiers and accounts associated with a person of interest that were previously unknown. Breached credentials are especially pivotal in the investigation of threat actors because even individuals with strong operational security (OPSEC) make small mistakes like reusing email addresses, usernames, or passwords across different platforms. Historical databases from older accounts, created before a person of interest adopted rigorous OPSEC techniques, can often reveal additional identifiers or patterns in username or password selection.
Highlights
- District 4 Labs builds next-gen OSINT tools, with DARKSIDE as its flagship, one of the world's largest breached data and person-of-interest repositories. Used by federal law enforcement, intelligence agencies, private investigators, penetration testers, MSSPs, and corporate security teams, DARKSIDE helps investigate persons of interest, mitigate risk, and uncover critical intelligence.
- DARKSIDE now ingests millions of stealer logs with billions of records, adding tens of thousands daily. By merging historic breach data with fresh log stealer intel, it empowers investigators to identify threat actors, disrupt attacks, and enhance OSINT. Logs include autofills, cookies, credentials, and credit cards, offering deep insight into a subject's digital footprints and real-time threat attribution.
- DARKSIDE focuses on PII from global breached data spanning 20 plus years. The data is uniquely parsed and structured to enable intuitive and efficient searches by email, IP, phone, alias, and more, revealing hidden connections even seasoned threat actors miss. Access is available via our proprietary user interface (UI), an easy to integrate REST API, and through integrations with leading OSINT platforms for vetted investigators and organizations.
Details
Introducing multi-product solutions
You can now purchase comprehensive solutions tailored to use cases and industries.
Features and programs
Financing for AWS Marketplace purchases
Pricing
Dimension | Description | Cost/12 months |
|---|---|---|
Darkside API Calls Subscription | Annual Subscription with up to 5,000 Monthly API Calls | $60,000.00 |
Darkside UI Subscription | Annual Subscription with up to 3 Users and 750 Monthly Searches | $20,000.00 |
Vendor refund policy
No cancellation or refunds unless agreement terms are breached.
How can we make this page better?
Legal
Vendor terms and conditions
Content disclaimer
Delivery details
Software as a Service (SaaS)
SaaS delivers cloud-based software applications directly to customers over the internet. You can access these applications through a subscription model. You will pay recurring monthly usage fees through your AWS bill, while AWS handles deployment and infrastructure management, ensuring scalability, reliability, and seamless integration with other AWS services.
Resources
Vendor resources
Support
Vendor support
AWS infrastructure support
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.