
Dissecting the Dark Web
Reverse Engineering the Tools of the Underground Economy
HUMAN Security's VP of Threat Intelligence tears down real malware-as-a-service offerings sold on dark web forums, chapter by chapter, from stealers and loaders to ransomware and living-off-the-land post-exploitation kits.
As an Amazon Associate we earn from qualifying purchases. The link above is sponsored.
- Authors
- Lindsay Kaye
- Published
- 2026
- Publisher
- No Starch Press
- Pages
- 400
- Language
- English
Read this if
Threat intelligence analysts and reverse engineers who want technical breakdowns of what's actually sold on dark web forums, not a policy or law-enforcement overview of the dark web as a phenomenon. Kaye is a working malware analyst, and the chapters mirror a MaaS buyer's catalog: stealers, banking trojans, packers, C2 frameworks, post-exploitation toolkits, ransomware.
Skip this if
Readers wanting an investigative or sociological account of dark web marketplaces (closer to Dark Wire or American Kingpin); this is reverse-engineering technique applied to underground tooling, not narrative journalism.
Key takeaways
- Organized around the actual malware-as-a-service economy structure, treating the dark web as a supply chain to be torn down tool by tool.
- Covers the full toolkit lifecycle sold underground: delivery, stealers, packers, C2, post-exploitation, and both Windows and Linux/ESXi ransomware.
- Living-off-the-land technique gets dedicated treatment, reflecting how much underground tooling now avoids custom malware entirely.
Notes
The reverse-engineering counterpart to this catalog's narrative dark-web and cybercrime books (Dark Wire, American Kingpin, Spam Nation) — those tell the human and investigative story, this one tears down the actual tools being sold. Pairs naturally with Practical Malware Analysis and Evasive Malware for the analysis technique applied here.
What to read before
What to read before Dissecting the Dark Web →Intermediate · 2010
Cybercriminalité
A practitioner's treatment of cybercrime law — offences, procedure, and the application of criminal law to digital crime — by a French magistrate specialised in the field.
Advanced · 2025
Cybersécurité et Malwares
Now in its 5th edition, the French-language reference for malware analysis by Sébastien Larinier and Paul Rascagnères, a well-known APT threat researcher, running from identification to Threat Intelligence across Windows, macOS, Linux, Android, and iOS.
Beginner · 2022
The Ransomware Hunting Team
Investigative journalism on the volunteers who quietly cracked ransomware to free victims for free, while the FBI mostly watched. A people-first look at the early ransomware economy.
What to read next
What to read after Dissecting the Dark Web →Advanced · 2025
Cybersécurité et Malwares
Now in its 5th edition, the French-language reference for malware analysis by Sébastien Larinier and Paul Rascagnères, a well-known APT threat researcher, running from identification to Threat Intelligence across Windows, macOS, Linux, Android, and iOS.
Advanced · 2014
The Art of Memory Forensics
Ligh, Case, Levy, and Walters' canonical reference on memory analysis with Volatility — the technique, the tooling, and the operating-system internals it depends on, across Windows, Linux, and macOS.
Advanced · 2025
Data Engineering for Cybersecurity
A decade-plus threat analyst teaches how to collect, normalize, enrich, and secure the telemetry (logs, events, metrics) that security teams depend on, using open-source tools like Filebeat, Logstash, Redis, Kafka, and Elasticsearch.
Explore similar books
Alternatives to Dissecting the Dark Web →Advanced · 2025
Cybersécurité et Malwares
Now in its 5th edition, the French-language reference for malware analysis by Sébastien Larinier and Paul Rascagnères, a well-known APT threat researcher, running from identification to Threat Intelligence across Windows, macOS, Linux, Android, and iOS.
Beginner · 2022
The Ransomware Hunting Team
Investigative journalism on the volunteers who quietly cracked ransomware to free victims for free, while the FBI mostly watched. A people-first look at the early ransomware economy.
Advanced · 2014
The Art of Memory Forensics
Ligh, Case, Levy, and Walters' canonical reference on memory analysis with Volatility — the technique, the tooling, and the operating-system internals it depends on, across Windows, Linux, and macOS.