Threat › Module 1 › Lesson 3
No Criminal Markets
No criminal markets means refuse marketplace access guides, stolen credential purchases, and unauthorized dark-web browsing — write the refusal habit into YOUR $TI_LAB ethics card.
Visual · t33_no_criminal_markets
Marketplace refusal. $TI_LAB only. Original Cyberlium.
Opening
Criminal marketplace threads, stolen credential drops, and unauthorized dark-web access — all stop outside authorized defensive scope. Literacy names the risk; collection stays on lab IOCs.
Unauthorized TI collection includes browsing criminal marketplaces for live IOCs, purchasing stolen credentials for 'research,' impersonating buyers on fraud forums, and scraping victim data without legal authorization. Org scope follows ownership: employer TI platforms and law-enforcement channels require written scope — criminal markets stay off limits. Cyberlium practices refusal sentences on YOUR $TI_LAB — 'I practice TI on fictional lab IOCs and name risks for defender context' — never copy forum threads that aim collection at criminal marketplaces. Next: Lab Setup.
1. Criminal marketplace patterns refused (named, literacy only)
Marketplace access guides: step-by-step instructions to browse criminal forums — named for literacy, NOT executed on Cyberlium. Stolen credential purchases: buying access for 'TI research' — defender fix is legal collection channels and org authorization, not student replication.
On $TI_LAB, write three refusal triggers — e.g., marketplace access request, stolen credential purchase, unauthorized dark-web browsing tutorial.
Command guide
Try these commands — Criminal marketplace patterns refused (named, literacy only)
═══ TOOLS & WEBSITES ═══ Browse / read these (authorized learning only — stay in YOUR lab / program scope)
FIRST ethics — https://www.first.org/global-sigs/trusted-introducer (trusted sharing norms) CISA — https://www.cisa.gov/ (legal defensive TI context) MITRE ATT&CK — https://attack.mitre.org/
═══ INSTALL ═══
Linux (Debian/Ubuntu):
Command — copy this
sudo apt install python3
macOS:
Command — copy this
brew install python3
Windows: Download https://python.org/downloads/
═══ LINUX / macOS ═══
Command — copy this
export TI_LAB=${TI_LAB:-$HOME/cyberlium-lab/t33-ti}
cat > "$TI_LAB/notes/no-criminal-markets.txt" <<'EOF'
SCOPE: YOUR lab folder $HOME/cyberlium-lab/t33-ti/ — fake IOCs + markdown notes only
NEVER: buying access; carding forums; hacking forums howto; doxxing
NEVER: tor marketplace steps; criminal marketplace cookbooks; real victim PII
ALLOWED: fake IOCs (example.com, RFC1918, EICAR labels); ATT&CK mapping; STIX stubs
PURPOSE: defensive TI literacy — consume, map, report — not criminal collection
EOFCommand — copy this
grep -E 'SCOPE|NEVER|ALLOWED' "$TI_LAB/notes/no-criminal-markets.txt"
python3 -c "print('Ethics: criminal market access = legal risk — YOUR fake IOC lab only')"Primary tools to practice this lesson: grep, python3. Reference sites: FIRST ethics (https://www.first.org/global-sigs/trusted-introducer); CISA (https://www.cisa.gov/); MITRE ATT&CK (https://attack.mitre.org/). Run every command in the box — install first, then the usage lines — only on YOUR lab / program scope.
2. Why refusal protects you and others
Unauthorized collection violates laws, platform terms, and employer policy — skill without scope is career and legal risk. Victim harm: using stolen credentials or victim IOCs without authorization hurts real people you must not enable.
Defenders collect through authorized feeds, ISACs, vendor reports, and legal OSINT — students practice naming these channels for hardening notes on lab scenarios only.
3. Ethics card habit
Forbidden: sharing marketplace access links in class chat, importing criminal forum IOC dumps, purchasing stolen data for labs. Allowed: ethics card — allowed lab IOC sources, NEVER list, refusal sentence you will say aloud.
Ship: TI ethics card with NEVER list and one refusal sentence. Next: Lab Setup.
4. What you ship: TI ethics card for $TI_LAB
Allowed lab IOC sources, NEVER list, refusal sentence. $TI_LAB named. NO criminal markets. chmod 600.
5. What you record before the next lesson
Date. Ethics card. $TI_LAB named. File t33-m01-l03-no-criminal-markets.txt chmod 600.
6. Wrong vs right: criminal markets vs YOUR lab IOCs
Worked failure — same MSF word, opposite target. Right never needs a café Wi-Fi or classmate laptop.
Wrong
Follow marketplace access tutorial 'for detection.' Share criminal forum IOC dump in Discord.
Right
Write TI ethics card for YOUR $TI_LAB. Next: Lab Setup.
Mission: write YOUR criminal-market refusal habit
1) List three NEVER targets (marketplace access, stolen credentials, unauthorized dark-web browsing). 2) Write one refusal sentence for criminal collection requests. 3) Name allowed $TI_LAB IOC sources. 4) chmod 600.
Stuck? Ask Cyberlium AI Mentor
Name risks for defender context — never replicate criminal marketplace collection in lab.
Knowledge Check
APPLY: No criminal markets on Cyberlium means:
Multiple choice
Knowledge Check
APPLY: True or False: TI collection is taught with fictional lab IOCs only — not criminal marketplace access.
True or False
Knowledge Check
APPLY: Discord link to criminal marketplace access guide — you:
Multiple choice