IoT firmware penetration testing benchmark
IoT firmware penetration testing benchmark on OWASP IoTGoat, real results only: a static firmware image unpacked to find the backdoor daemon and a Mirai default credential, and a live appliance rooted through an unauthenticated backdoor, each proven with a working exploit.
Darkmoon, the open source autonomous AI penetration testing tool, found 29 IoT vulnerabilities across 2 OWASP IoTGoat runs and proved 4 of them with a real exploit, one from a firmware image alone and one against a live device.
S.03Attack chainsWhat each run proved
Every tile opens the long-form write-up. The chip is the report's own findings total; the line above the title is its exploited count and severity split.
A static image unpack found the backdoor daemon, telnetd and a Mirai default credential before power-on.
Root through the port-5515 backdoor on a live appliance, /etc/shadow pulled, the Mirai SSH credential cracked.
Read the IoT firmware penetration testing methodology before the two case studies.
S.04ResultsIoT runs, finding by finding
Each row links to its long-form write-up and to the raw report in the research corpus.
DisclaimerDarkmoon's own benchmark on the public OWASP IoTGoat lab.
The offensive runs are produced by the open source Darkmoon CLI; the web dashboard and the remediation-to-PR loop are paid Pro. Raw reports live in the darkmoon-research corpus and the results feed the Darkmoon-Benchmarks leaderboard.
S.06More benchmarksKeep exploring the benchmarks
AWS and Azure cloud penetration testing benchmark
AWS, Azure and GCP identity, storage and metadata chains.
CI/CD and infrastructure pentest benchmark
Jenkins, Redis, PostgreSQL, Terraform, Vault, GitLab and the Docker socket.
Web app pentest benchmark: OWASP Juice Shop
OWASP Juice Shop, black-box, six-campaign escalation.
How Darkmoon compares to other AI pentest tools
Verifiable facts only, with honest credit where competitors lead.
S.07FAQIoT benchmark questions
What does the IoT firmware penetration testing benchmark cover?
What does the IoT firmware penetration testing benchmark cover?
Two autonomous runs against OWASP IoTGoat: a static firmware image analysis that found the backdoor daemon, the telnet daemon and a Mirai default credential before power-on, and a live device run that reached root through the port-5515 backdoor and cracked the Mirai SSH credential.
How many IoT vulnerabilities did Darkmoon find?
How many IoT vulnerabilities did Darkmoon find?
Darkmoon, the open source autonomous AI penetration testing tool, found 29 IoT vulnerabilities across 2 runs on OWASP IoTGoat and proved 4 of them with a real exploit, including root on the live appliance and cracking the Mirai default credential.
Can Darkmoon test firmware without a physical device?
Can Darkmoon test firmware without a physical device?
Yes. The static firmware run unpacked the image and found the backdoor, telnetd and a Mirai default credential without ever powering the device. The open source Darkmoon CLI performs both the static and the live assessment; the web dashboard and the remediation-to-PR loop are paid Pro capabilities.
S.08NextTest your own firmware and devices
Open source, self hosted and local first. Unpack an image or point Darkmoon at a device you own. A star helps other teams find it.