Find the root cause
A three-phase security audit traces each proven finding from the vulnerable sink back to its root cause in the target's own code. Security issues only, no style noise.
Autonomous, continuous penetration testing
50 specialist AI agents, 140+ security tools and a live command center. Darkmoon runs the full offensive campaign across web, cloud, Active Directory, Kubernetes, CI/CD, firmware and AI/LLM endpoints, then qualifies every finding EXPLOITED, CONFIRMED or UNCONFIRMED with an adversarial rubric.
140+ security tools, every one behind a build-enforced allow-list
Darkmoon's Pro remediation agent picks up where the pentest ends. For each confirmed finding it audits the target's own source for the root cause, writes the smallest correct fix, proves it in an ephemeral sandbox, and opens a pull request for your team to review. It never merges on its own.
A three-phase security audit traces each proven finding from the vulnerable sink back to its root cause in the target's own code. Security issues only, no style noise.
The exploit is reproduced against a fresh build, the fix applied, then the exploit and its variants re-run to prove they now fail while the app's normal behaviour and its tests still pass.
A minimal root-cause patch is pushed to a branch and a pull request is opened, carrying the before/after evidence. GitHub, GitLab, Gitea, Bitbucket and Azure DevOps are supported.
Every pull request is a proposal for a person to review and merge. Darkmoon never auto-merges, and any fix it could not fully validate is opened as a clearly marked draft.
In the dashboard, every finding gains a PR column linking to the pull request that addresses it: forge URL, state, linked findings, diff stat and the before/after validation.
Push credentials are sealed at rest and resolved locally. The run carries only an opaque reference, never the token, so your secret never enters the model's context.
It joins a roster of 52 agents: an orchestrator, 50 offensive specialists (web, cloud, Active Directory, Kubernetes, databases and an llm agent that runs the OWASP LLM Top 10 against exposed AI/LLM inference endpoints) and this Pro remediation agent.
See the Pro remediation benchmark: fixes proven by re-running the exploit · Compare Darkmoon with other AI pentest tools
Scope in, agents dispatched, findings qualified, report out. Not a feature tour: the product running against a real target.
Darkmoon reasons about your target, models the attack surface and dispatches the right agents across web, cloud, identity, Kubernetes, CI/CD, firmware and AI/LLM endpoints, with full cascade control.
The orchestrator fingerprints 14 technology signals and routes the campaign to the right specialists across web, cloud, Active Directory, Kubernetes, CI/CD, firmware and AI/LLM endpoints, sequential or parallel, with cascade depth capped at three levels so there is never runaway recursion.
Learn moreOpen source at the core. One licence to run the full autonomous platform.
Open source, self-host it forever
Star on GitHubFree forever, GPLv3
What's included:
For professional pentesters & teams
Get DarkmoonBilled €1788 annually
Everything in Community, and:
For enterprises, MSSPs & resellers
Contact salesTailored to your scope
Everything in Pro, and:
The orchestrator fingerprints your target's stack and dispatches the right specialists automatically, from web and cloud to Active Directory, Kubernetes, CI/CD and firmware. A dedicated llm agent covers the OWASP LLM Top 10, and on Pro a remediation agent turns confirmed findings into sandbox-validated fix pull requests for your team to review.
SQLi, XSS, SSRF, IDOR, RCE, SSTI, deserialization, JWT abuse, file upload and path traversal, validated with real payloads, never signatures.
AS-REP roasting, Kerberoasting, NTLM relay, DCSync and ADCS ESC1-ESC8, plus IMDS token minting, Key Vault extraction and ROPC pivots, each proven with the exact call.
Binwalk/squashfs extraction, backdoor recovery and router exploitation, Kubernetes RBAC and node escape, and a dedicated llm agent for the OWASP LLM Top 10.
Darkmoon's runtime guard enforces tamper-proof execution, sealed storage and hardware-bound licensing from the moment the container starts.
Agents and workflows are encrypted at rest. Keys derive from your licence and hardware fingerprint, resealed every 30 seconds.
Machine code derives from MAC address and CPU model. No deployment ID to spoof, no env var to manipulate.
SHA-256 hashes of critical binaries are re-verified every 2 seconds. Any tampering triggers an immediate zeroize.
Continuous scanning for gdb, strace, ltrace, frida and lldb. Any tracer triggers a breach and full state zeroize.
Read-only filesystem, tmpfs writable paths, seccomp and no-new-privileges. The process runs unprivileged.
Every model API key and the licence key are scrubbed from stdout and stderr before any log output.
The Privacy Gateway tokenizes every sensitive value on your machine, IPs, hostnames, domains, URLs, emails, credentials, internal paths, before it ever reaches the model. Claude reasons only on deterministic placeholders. Real values are re-injected locally, an instant before each tool runs, then masked back out of every output. Keep Claude's full power, or run a fully local, self-hosted model for end-to-end sovereignty.
No sensitive data is ever sent to the LLM.
Deterministic tokens (same value → same placeholder), Fernet-encrypted in memory, never logged. Every IP, hostname, URL, email, credential and internal path is replaced by a stable placeholder such as IP_PRIVATE_001, so the model can still reason about relationships between hosts without ever seeing a real value. The mapping is per session, HMAC-deduplicated, and destroyed when the run ends.
Context-aware rehydration of whitelisted fields only, two-pass output sanitisation. Real values are re-injected an instant before each tool runs, only where the field is explicitly allowed, never with a naive global replace. Everything the tool prints is masked again before it returns to the model, in two passes, so a placeholder never leaks back as its real value.
Exfiltration blocked: placeholder in a URL, external host, echo/print, POST body, /dev/tcp, nc/telnet. The gateway inspects every command the model proposes and refuses any that would carry a placeholder or a real value outside your host, whether through a web request, a raw socket, a shell redirect or a simple print. The attempt is logged as blocked and the run continues.
On a full end-to-end run with the gateway active throughout, the model reasoned about the target the whole time yet saw its real address zero times across roughly 3.5 MB of model-facing traffic. The deterministic placeholder carried the reasoning; the real values were restored only on your host, in the final report. One measured run, not a blanket guarantee.
Reversible tokenization + anti-exfiltration gateway ship open-source. Sealed vault, rehydration audit trail and compliance proof are Pro.
Darkmoon's architecture is its security guarantee, and it's fully auditable. The AI reasons and writes the plan. An MCP gateway gatekeeps every tool call. Read it, then run it yourself.
Turn your infrastructure into a dedicated autonomous security node. Software-defined. Self-hosted. No proprietary hardware.
The same open-source engine, wired into your IDE, your CI/CD, your automation and your SecOps stack. Each surface auto-detects its edition: the community CLI runs on your local JSON report; the paid Pro tier adds the live REST API, streaming and remediation.
Run the full platform on your own infrastructure. Hardware-bound licence, Docker install, monthly or annual.
Describe your target, sign the framework online, pay a flat rate. Our experts run it and deliver a debriefed report.
Resell Darkmoon under your own commercial wrapper. One dashboard, every licence, Stripe-powered billing built in.
Describe your target, sign the framework online, pay a flat rate, our experts run the full offensive engagement and deliver a debriefed, evidence-backed report to your secure client space.
Darkmoon orchestrates an end-to-end offensive campaign, it reasons about the target, dispatches domain specialists, validates findings with real payloads, builds an infrastructure graph and produces a structured report. A scanner runs one-pass signatures. Darkmoon runs a pentest.
By design. The model plans and reasons, but every tool invocation passes through an MCP gateway that validates and gatekeeps the call. The model never executes a shell directly, which keeps the engagement auditable, bounded and safe. The whole architecture is open source.
Yes. The engine is published on GitHub at ASCIT31/Dark-Moon under the GPLv3 licence. You can read the orchestration logic, the agent playbooks and the MCP layer, and self-host it. The commercial licence adds the hardened runtime, the managed dashboard and support.
ISO 27001 standard, HackerOne, Bugcrowd (VRT / P1–P5) and a custom format. Every report includes CVSS 3.1 scoring, MITRE ATT&CK mapping, ISO 27001 controls, raw evidence and remediation guidance. PDF export is branded and password-protected.
Darkmoon uses hardware-bound licensing. Your licence key is tied to a machine fingerprint derived from your hardware (MAC address, CPU model), it cannot be cloned or moved to another machine by changing an environment variable.
Darkmoon includes configurable noise levels (stealth, low, moderate), safe-harbor mode, out-of-scope enforcement and per-agent scope propagation. The runtime is hardened with a read-only filesystem, seccomp, no-new-privileges and continuous watchdog checks.
Live visibility, validated evidence and a report your team can act on the same day.