Authors - Swetha P. , Maniratnam, Prasad B Honnavalli Abstract - The dark web has been identified as a major source of organizational risk, facilitating underground markets for stolen credentials, proprietary data, and pre-attack threat intelligence. An organization lacking visibility in these underground marketplaces faces attacks entirely beyond conventional monitoring solutions. This paper introduces a realtime dark web monitoring system integrating anonymous browsing via Tor, Selenium WebDriver, and open-source Wazuh Security Information and Event Management (SIEM) to create a unified threat intelligence solution. The system performs continuous keyword searching for organizational name references and autonomously browses authenticated dark web marketplaces for content extraction. Identified events are serialized as structured JSON messages and ingested into Wazuh via custom decoder and rule definitions, providing actionable alerts on the analyst dashboard within seconds. The system has been evaluated over 24-hour continuous sessions on two live dark web markets, achieving 95% keyword detection accuracy, 1.4 seconds average alert latency to dashboard, and stable long-duration browser operation without application crashes. The system requires no commercial licensing, is fully configurable to organizational targets, and features native SIEM integration, making it a viable and accessible solution compared to proprietary dark web intelligence services.