S.01For self-hosted & sovereign environments

Local-LLM pentesting that never leaves

Most autonomous AI pentesters send your code, IPs and traffic to a hosted model. Darkmoon can run entirely on a local LLM, with a Privacy Gateway that keeps sensitive values away from the model, so it is safe to point at production or a client environment.

57
Juice Shop findings on a local model
0
Times the model saw the target (3.5 MB)
42/57
Findings fixed and retested (Pro)
GPL-3.0
Self hosted via docker-compose
S.03Your wedge

The message no leader owns

Local model, tokenized data, readable source, the wedge the high-star cloud tools do not have.

Local LLM by default

Run against Ollama or llama.cpp on your own hardware. The 57-finding OWASP Juice Shop benchmark was produced black-box on a local model, proof the local path works.

Learn more

S.04What you get
What sovereignty means here

01
$darkmoon run --scope identity
→AS-REP roast · 3 accounts
→Kerberoast · svc_sql cracked
→NTLM relay → DCSync
✓Domain Admin, proven

Nothing leaves your perimeter

With a local model and the Privacy Gateway, no source, no traffic and no credentials are shipped to a third party. This is a design guarantee you can read in the code.

02
FindingsCVSS
SQL injection9.8
SSRF to metadata9.1
Broken access control8.7
JWT signature bypass7.5
Path traversal6.9

Breadth in one tool

Web, API, Active Directory & identity, Kubernetes, cloud, CI/CD, databases, IoT/firmware and LLM endpoints, 50+ specialist agents, all running on your infrastructure.

03
Attack surfaceexposure

Reproducible, honest proof

The offensive benchmark and the 42/57 Pro remediation dossier publish their limits and invite you to reproduce or contest them, black-box, on a public lab.

S.05Start here
The pieces that matter to you

S.06Next
Keep the whole engagement in-house

Darkmoon is open source (GPL-3.0), self hosted, and runs on a local model. Clone it and read every line.