CI/CD and infrastructure pentest benchmark
CI/CD and infrastructure pentest benchmark across Jenkins, Redis, PostgreSQL, Terraform and Vault, real results only: Jenkins script console RCE, Redis unauthenticated exploitation, PostgreSQL COPY PROGRAM RCE, Terraform tfstate secrets exposed and a Docker socket container escape, each proven with a working exploit.
Darkmoon, the open source autonomous AI penetration testing tool, found 135 infrastructure vulnerabilities across 6 CI/CD and data-layer labs and proved 47 of them with a real exploit, from anonymous access to root on the host.
S.03Attack chainsWhat each run proved
Every tile opens the long-form write-up. The chip is the report's own findings total; the line above the title is its exploited count and severity split.
Guessed root token, image-layer secrets, and a Docker-socket container escape reading the host /etc/shadow.
An exposed terraform.tfstate and Ansible inventory chained to an AdministratorAccess CI key.
An admin PAT with api and sudo scopes, an unmasked AWS secret in CI/CD variables, and open signup.
PostgreSQL COPY TO PROGRAM RCE, pg_shadow and mysql.user hashes, and live session tokens.
Unauthenticated access and the admin session token extracted; the RDB-write RCE honestly demoted (Redis 7.x).
Anonymous HTTP to script-console RCE to the master encryption key. All three findings exploited.
S.04ResultsInfrastructure runs, finding by finding
Each row links to its long-form write-up and to the raw report in the research corpus.
| Lab / target | Findings | Severity | Exploited | Model | Evidence |
|---|---|---|---|---|---|
| Vault + registry + Docker socketcamp_20260801_2bd90d3f | 41 | 15C15H9M2L | 8 | claude-opus-4-6 | Write-upReport |
| Terraform + AWS + Ansiblecamp_20260801_b1b96939 | 34 | 21C5H8M | 16 | claude-opus-4-6 | Write-upReport |
| GitLab CE 19.2.1camp_20260801_a719641d | 26 | 4C8H10M2L2I | 2 | claude-opus-4-6 | Write-upReport |
| PostgreSQL 16 + MySQL 5.6camp_20260801_c0151524 | 22 | 6C10H6M | 13 | claude-opus-4-6 | Write-upReport |
| Redis 7.4.10 (unauth)camp_20260801_96be38b9 | 9 | 3C5H1M | 5 | claude-opus-4-6 | Write-upReport |
| Jenkins 2.541.3 (security off)camp_20260801_b6ad197d | 3 | 3C | 3 | claude-opus-4-6 | Write-upReport |
DisclaimerDarkmoon's own benchmark on public infrastructure labs.
The offensive runs are produced by the open source Darkmoon CLI; the web dashboard and the remediation-to-PR loop are paid Pro. Raw reports live in the darkmoon-research corpus and the results feed the Darkmoon-Benchmarks leaderboard.
S.06More benchmarksKeep exploring the benchmarks
AWS and Azure cloud penetration testing benchmark
AWS, Azure and GCP identity, storage and metadata chains.
IoT firmware penetration testing benchmark
OWASP IoTGoat, static firmware and a live appliance.
Web app pentest benchmark: OWASP Juice Shop
OWASP Juice Shop, black-box, six-campaign escalation.
Automated remediation benchmark (Pro): 42 of 57 fix PRs
57 findings, 57 pull requests, 42 demonstrated end to end on OWASP Juice Shop; the 15 excluded cases are disclosed in full.
S.07FAQInfrastructure benchmark questions
What does the CI/CD and infrastructure pentest benchmark cover?
What does the CI/CD and infrastructure pentest benchmark cover?
Six autonomous runs against Jenkins, Redis, PostgreSQL and MySQL, Terraform with AWS and Ansible, HashiCorp Vault with a container registry and the Docker socket, and GitLab. Highlights include Jenkins script console RCE, Redis unauthenticated exploitation, PostgreSQL COPY PROGRAM RCE, Terraform tfstate secrets exposed and a Docker socket container escape.
How many infrastructure vulnerabilities did Darkmoon find?
How many infrastructure vulnerabilities did Darkmoon find?
Darkmoon, the open source autonomous AI penetration testing tool, found 135 infrastructure and CI/CD vulnerabilities across 6 labs and proved 47 of them with a real exploit. The Redis run also honestly demoted the classic RDB-write RCE, because Redis 7.x mitigates it.
Was the infrastructure benchmark run on a local model?
Was the infrastructure benchmark run on a local model?
This lab wave ran on claude-opus-4-6 through the open source Darkmoon CLI, which can also run on a local model (Ollama or llama.cpp). The Privacy Gateway tokenizes real values so the model works on placeholders. The web dashboard and the remediation-to-PR loop are paid Pro capabilities.
S.08NextRun these checks in your own pipeline
Open source, self hosted and local first. Wire Darkmoon into CI/CD and gate the build on exploited findings. A star helps other teams find it.