S.01IoT benchmark

IoT firmware penetration testing benchmark

IoT firmware penetration testing benchmark on OWASP IoTGoat, real results only: a static firmware image unpacked to find the backdoor daemon and a Mirai default credential, and a live appliance rooted through an unauthenticated backdoor, each proven with a working exploit.

29
IoT vulnerabilities
2
OWASP IoTGoat runs
4
proved with a real exploit

Darkmoon, the open source autonomous AI penetration testing tool, found 29 IoT vulnerabilities across 2 OWASP IoTGoat runs and proved 4 of them with a real exploit, one from a firmware image alone and one against a live device.

S.04Results
IoT runs, finding by finding

Each row links to its long-form write-up and to the raw report in the research corpus.

Lab / targetFindingsSeverityExploitedModelEvidence
IoTGoat firmware imagecamp_20260802_dd187131204C7H7M2L1claude-opus-4-6Write-upReport
IoTGoat live devicecamp_20260802_257f75f194C3H2M3claude-opus-4-6Write-upReport

Disclaimer
Darkmoon's own benchmark on the public OWASP IoTGoat lab.

The offensive runs are produced by the open source Darkmoon CLI; the web dashboard and the remediation-to-PR loop are paid Pro. Raw reports live in the darkmoon-research corpus and the results feed the Darkmoon-Benchmarks leaderboard.

S.07FAQ
IoT benchmark questions

What does the IoT firmware penetration testing benchmark cover?

Two autonomous runs against OWASP IoTGoat: a static firmware image analysis that found the backdoor daemon, the telnet daemon and a Mirai default credential before power-on, and a live device run that reached root through the port-5515 backdoor and cracked the Mirai SSH credential.

How many IoT vulnerabilities did Darkmoon find?

Darkmoon, the open source autonomous AI penetration testing tool, found 29 IoT vulnerabilities across 2 runs on OWASP IoTGoat and proved 4 of them with a real exploit, including root on the live appliance and cracking the Mirai default credential.

Can Darkmoon test firmware without a physical device?

Yes. The static firmware run unpacked the image and found the backdoor, telnetd and a Mirai default credential without ever powering the device. The open source Darkmoon CLI performs both the static and the live assessment; the web dashboard and the remediation-to-PR loop are paid Pro capabilities.

S.08Next
Test your own firmware and devices

Open source, self hosted and local first. Unpack an image or point Darkmoon at a device you own. A star helps other teams find it.