GovernmentCybersecuritySecurity Operations

How CACI's DarkBlue Uses Elasticsearch and Claude to Accelerate Dark Web Criminal Investigations

CACI's DarkBlue Intelligence Suite is a cloud-based platform that enables national security agencies, law enforcement, and intelligence teams to search and analyze dark web and open-source intelligence (OSINT) data to identify and deanonymize criminals. Built on Elasticsearch and Elastic Observability, DarkBlue's newest feature, CluesAI, harnesses Anthropic Claude LLMs via AWS Bedrock to generate automated intelligence reports that connect criminal personas across the dark web in seconds.

Impact

Seconds per query regardless of data age or volume

Criminal investigation acceleration

Countless hours saved

Analyst time saved on lead investigation

Rapid — no new software stack needed

New data source integration time

Full dark web search without browser exposure

Client safety

Challenge

CACI needed a search and analytics foundation capable of ingesting massive, unstructured dark web and OSINT datasets from constantly evolving sources, delivering search results in seconds regardless of data volume or age, and enabling law enforcement clients to investigate criminal activity without the security risks of accessing the dark web directly.

Solution

Elasticsearch and Elastic Observability power DarkBlue's core search and analytics platform, using Elastic Agents, Fleet, Kibana, and persistent data archiving to enable OSINT investigation across dark and open web sources. CluesAI, built on Anthropic Claude LLMs via AWS Bedrock, adds automated intelligence report generation to deanonymize threat actors.

Tools & Technologies

What Leaders Say

Elastic's search and pivot capabilities allow us to connect the dots. We can often link anonymous personas to a single actor with just one query.

Cory Everington, Head of the DarkBlue Intelligence Suite, CACI

Elastic helps us move quickly. It simplifies the process of integrating new data sources and removes the need for complex setup across multiple applications.

Cory Everington, Head of the DarkBlue Intelligence Suite, CACI

Our clients trust us, and we trust Elastic. We count on Elastic to help us track criminal activity across hidden spaces online.

Cory Everington, Head of the DarkBlue Intelligence Suite, CACI
Get the full context.

Sign up to read complete case studies, access detailed metrics, and unlock all use cases.

Full Story

The dark web hosts illegal activities—drug trafficking, arms trading, ransomware sharing, human trafficking—worth over $4 billion. CACI is an international leader in dark web analysis. Its DarkBlue Intelligence Suite enables national security and intelligence teams to search open-source intelligence (OSINT) and unmask criminals operating on the dark web, with additional expansion to other open web sources hosting illicit activity.

Building a platform to search and analyze this volume of unstructured, constantly shifting data required infrastructure capable of ingesting diverse data sources at scale, delivering search results in seconds regardless of data age, and enabling clients to analyze data without exposing themselves to the dark web's inherent risks.

DarkBlue chose Elasticsearch and Elastic Observability as the core of its platform from the beginning. Running on AWS cloud with Elastic Agents and Fleet for data collection, DarkBlue can ingest structured and unstructured data from almost any source using schemas and templates set up once—without needing to build new software and connections for each. Kibana makes it easy to visualize and query large volumes of ingested data in real time. Filter functionality and keyword fields enable exact matching on targeted selectors, while Boolean operations, fuzzy matching, and full-text search allow investigators to explore data in the ways investigations demand. Elasticsearch also archives data indefinitely, enabling investigators to trace criminal personas that change identities over time.

The platform's newest capability, CluesAI, adds generative AI to the workflow. Harnessing Anthropic Claude LLMs via AWS Bedrock, CluesAI cross-references potentially identifying information across the dark web dataset maintained in Elasticsearch and generates automated intelligence reports—saving analysts and investigators countless hours of manually running down leads to deanonymize threat actors.

With DarkBlue, law enforcement clients can search for information without downloading a dark web browser or exposing themselves to malware or disturbing content. Searches complete in seconds regardless of the data's age or source. Seamless integration of new data sources—including leading crypto analyst firms added for cryptocurrency investigation—means the platform evolves alongside the dark web itself.

"Elastic's search and pivot capabilities allow us to connect the dots. We can often link anonymous personas to a single actor with just one query," said Cory Everington, Head of the DarkBlue Intelligence Suite.

Similar Cases

S
Stairwell
40,000+ characters
security data processed per claude request

Stairwell, a cybersecurity company, integrated Claude into its Maleval threat detection platform to summarize complex security findings for analysts. Claude's large context window allows it to process 40,000+ character API responses in a single pass, converting dense technical data into clear, actionable insights with minimal prompt engineering.

CybersecurityTechnologyCClaude
B
BigID
120x
query speed improvement

BigID, a data security, privacy, compliance, and AI data management platform founded in 2016, deployed Elasticsearch on Elastic Cloud and AWS to overcome severe query performance degradation as its customer data volumes grew. By migrating its core data-driven modules to Elasticsearch, BigID cut query times from 20 minutes to seconds — a 120x speedup — eliminated all query timeouts on search, dashboard, and reporting modules, and built a foundation capable of handling billions of records with complex filtering and aggregation.

CybersecurityEElasticsearch
C
Cogent
97% faster
vulnerability resolution speed

Cogent built an AI-powered cybersecurity platform with Claude as the reasoning layer, reducing critical vulnerability exposure from days/weeks to minutes — a 97% reduction — while reclaiming 40+ hours monthly from manual reporting.

CybersecurityCAClaude API
V
Vectorize.io
~2 hours
time to deploy ai solution for new client

Vectorize.io is a US-based software company that builds agentic and generative AI infrastructure, helping organizations in law, insurance, and finance make vast volumes of unstructured data usable by large language models. By integrating Elastic’s hybrid search and Elastic Cloud Serverless with Amazon Bedrock, Vectorize deploys production-ready AI solutions for clients in hours rather than weeks. One client whose developer community grew by a million users in a year relied on Vectorize’s real-time learning agent—built on Elasticsearch—to answer support queries and instantly index new answers for future use.

ABAmazon BedrockEElasticsearch
A
ASAPP
91%
first-call resolution rate

ASAPP is an AI-native customer service platform that orchestrates large language models to automate contact center interactions for enterprise clients. By deploying Anthropic’s Claude through Amazon Bedrock, ASAPP eliminated its homegrown PII redaction layer and reduced call escalations by up to 40%, while helping clients achieve a 91% first-call resolution rate. The platform now automates more than 90% of contact center interactions, with human agents freed to handle three times the volume of complex cases.

TechnologyABAmazon BedrockCClaude
T
Trellix
Days → minutes
log parsing time

Trellix, a global cybersecurity firm serving 40,000+ enterprise customers, built Sidekick — an internal agentic platform powered by LangGraph and LangSmith — to automate log parsing and security integration development. What previously took engineers 2–3 days per request now takes minutes, and plugin development that spanned multiple days now completes in a single afternoon.

CybersecurityLLangSmithLLangGraph
NM
New Mexico County Assessor
+50 percentage points
improvement in model accuracy

New Mexico's largest county by population deployed C3 AI Property Appraisal to modernize its commercial property valuation process. By unifying millions of data points and applying AI-based Automated Valuation Models, the county achieved a 50-percentage-point improvement in model accuracy and a 3x gain in appraisal equity — all within weeks of going live.

GovernmentCAC3 AI Property AppraisalCAC3 AI Platform
M
ManTech
50%
it tier 1 fte reduction

ManTech deployed Moveworks' AI assistant to 8,000 federal government employees, cutting Tier 1 IT workload by 50%, reducing call center volume by 68%, and achieving 93% customer satisfaction in year one.

GovernmentMMoveworksASAgent Studio