IoT benchmark

IoT firmware penetration testing benchmark

IoT firmware penetration testing benchmark on OWASP IoTGoat, real results only: a static firmware image unpacked to find the backdoor daemon and a Mirai default credential, and a live appliance rooted through an unauthenticated backdoor, each proven with a working exploit.

Darkmoon, the open source autonomous AI penetration testing tool, found 29 IoT vulnerabilities across 2 OWASP IoTGoat runs and proved 4 of them with a real exploit, one from a firmware image alone and one against a live device.

Results

IoT runs, finding by finding

Lab / targetFindingsSeverityExploitedModelEvidence
IoTGoat firmware imagecamp_20260802_dd187131204C7H7M2L1claude-opus-4-6Write-up Report
IoTGoat live devicecamp_20260802_257f75f194C3H2M3claude-opus-4-6Write-up Report

New to the method? Read the IoT firmware penetration testing methodology before the two case studies.

Attack chains

What each run proved

IoTGoat firmware imageA static image unpack found the backdoor daemon, telnetd and a Mirai default credential before power-on.
IoTGoat live deviceRoot through the port-5515 backdoor on a live appliance, /etc/shadow pulled, the Mirai SSH credential cracked.
FAQ

IoT benchmark questions

What does the IoT firmware penetration testing benchmark cover?

Two autonomous runs against OWASP IoTGoat: a static firmware image analysis that found the backdoor daemon, the telnet daemon and a Mirai default credential before power-on, and a live device run that reached root through the port-5515 backdoor and cracked the Mirai SSH credential.

How many IoT vulnerabilities did Darkmoon find?

Darkmoon, the open source autonomous AI penetration testing tool, found 29 IoT vulnerabilities across 2 runs on OWASP IoTGoat and proved 4 of them with a real exploit, including root on the live appliance and cracking the Mirai default credential.

Can Darkmoon test firmware without a physical device?

Yes. The static firmware run unpacked the image and found the backdoor, telnetd and a Mirai default credential without ever powering the device. The open source Darkmoon CLI performs both the static and the live assessment; the web dashboard and the remediation-to-PR loop are paid Pro capabilities.

Darkmoon's own benchmark on the public OWASP IoTGoat lab. The offensive runs are produced by the open source Darkmoon CLI; the web dashboard and the remediation-to-PR loop are paid Pro. Raw reports live in the darkmoon-research corpus and the results feed the Darkmoon-Benchmarks leaderboard.

Test your own firmware and devices

Open source, self hosted and local first. Unpack an image or point Darkmoon at a device you own. A star helps other teams find it.