S.01Manufacturing, energy, water, transport

Penetration testing at the IT/OT boundary, never inside the PLC.

Darkmoon tests what connects your operations to the rest of the world: exposed HMIs and engineering web consoles, remote-maintenance VPNs, MES and ERP, the web front ends of historians, the CI/CD of your industrial software and your cloud tenants. It never fuzzes a PLC protocol or touches a safety system. The result is the path an attacker would take from the internet to the plant network, with the evidence of each step.

4th
most targeted EU sector in 2025-26: manufacturing, up from 7th (ENISA)
6.9 %
of EU events hit manufacturing; machinery and equipment the most affected subsector
€799
flat rate per managed engagement
50
specialist AI agents, 142 tools

S.03Industry & manufacturing
Why plants and utilities are exposed

ENISA ranks manufacturing the 4th most targeted EU sector in 2025-26, up from 7th the year before, at 6.9 % of events, with machinery and equipment the most affected subsector. On the utility side, ANSSI documented in 2025 continued hacktivist attempts against small renewable-energy installations whose control interfaces were exposed without authentication or with default passwords, and claimed compromises of water-sector equipment in which valve manipulation increased water flow, with limited impact. None of these began inside a PLC. They began on the IT side.

FindingsCVSS
SQL injection9.8
SSRF to metadata9.1
Broken access control8.7
JWT signature bypass7.5
Path traversal6.9

IT and OT meet in the same subnet

The MES polls the line, the ERP feeds the MES, the historian publishes to a web dashboard, and the Active Directory that authenticates the office also authenticates the engineering workstations. The boundary you drew on the architecture diagram is what Darkmoon tests from the IT side.

$darkmoon run --scope identity
→AS-REP roast · 3 accounts
→Kerberoast · svc_sql cracked
→NTLM relay → DCSync
✓Domain Admin, proven

Remote maintenance is a permanent door

Machine builders, integrators and utility contractors keep VPN profiles, cellular routers and remote-desktop jump hosts into the plant. Each one is an account somebody else manages, often without MFA, often never revoked when the contract ends.

Attack surfaceexposure

Exposed control interfaces, default passwords

Web HMIs of inverters, pumping stations, building controllers and small substations are reachable from the internet far more often than their owners believe. ANSSI's 2025 observations on renewable micro-installations and water equipment describe exactly that: no authentication, or the factory password.

darkmoon-licence.dmeDocker
LicencePro · annual
Machine code7F3A-…-C21E
Seats1 node
Statussealed ✓

Production is the ransom

Ransomware does not need to reach the controllers to stop a plant: encrypting the MES, the ERP, the file servers holding recipes and the engineering backups is enough. In September 2025 a ransomware attack on a check-in platform supplier disrupted several European airports, with no PLC involved.

S.04Attack surface
The attack surface of an industrial or utility operator

Six system families Darkmoon enumerates and attacks, from the internet inwards. Controllers, field devices and safety instrumented systems are excluded by design; the systems that reach them are the target.

HMI / SCADA web
Web HMIs and SCADA front ends reachable from outside

Internet-exposed or DMZ-published operator views of inverters, pumps, substations and lines: default credentials, missing authentication, outdated web stacks, management ports beside the HMI. Darkmoon tests the web layer and reachability, never the control protocol.

Remote maintenance VPN
Vendor and integrator access paths

SSL-VPN appliances, cellular gateways, remote-desktop jump hosts and vendor cloud relays. Exposed management interfaces, known CVEs on edge devices, accounts without MFA, routes from the maintenance network into engineering ranges.

MES / ERP
Manufacturing execution and enterprise systems

Order-to-line interfaces, recipe and batch management, quality modules, integrations with the ERP and the warehouse system. Authentication, role separation, APIs between MES and ERP, database exposure.

Historian
Web front ends and APIs of process historians

Dashboards and reporting portals that publish process data to the office network or to the cloud: authentication, query interfaces, write paths back towards the control network, exports to object storage.

Engineering consoles
Engineering workstations and web management consoles

Project repositories of PLC programs, licence servers, firmware and update servers, virtualised engineering hosts: the systems whose compromise lets an attacker change what runs on the line. Darkmoon tests how they are reached, not the program logic.

Cloud / CI/CD
Cloud tenants, IIoT platforms and software pipelines

AWS, Azure or GCP tenants receiving plant data, IIoT platforms and digital-twin back ends, the CI/CD pipelines and artefact registries of your industrial software and connected products, Kubernetes clusters hosting fleet services.

S.05Attack paths

How an attacker reaches the plant network.

Darkmoon chains findings into paths and keeps the evidence of each step. Four paths our agents look for in an industrial estate, all stopping at the boundary of the control system itself.

01
From an exposed HMI panel with the factory password to the process view

A web HMI of a pumping station or an inverter published on a public address, a password left at the manufacturer's default: the agent authenticates and documents what an operator view would allow. It records the finding and stops; it never sends a command to the process.

How the engine works

S.06What Darkmoon tests
What Darkmoon tests, and what it does not

Three engagement shapes, each run by an orchestrator and specialist agents behind an MCP gateway with a build-enforced allow-list. OT ranges are declared in the framework and handled passively or excluded; there is no protocol fuzzing of PLCs, RTUs or safety systems, in any edition.

web, edge, remote access
FindingsCVSS
SQL injection9.8
SSRF to metadata9.1
Broken access control8.7
JWT signature bypass7.5
Path traversal6.9

External surface: HMIs, consoles, VPN gateways

Internet-exposed HMIs and SCADA web front ends, vendor relays, SSL-VPN and remote-desktop gateways, IIoT portals, corporate web and mail. Web agents, edge-device CVE checks, default-credential and authentication testing; findings qualified EXPLOITED only when the login or the access is machine-verified.

AD, internal, reachability
$darkmoon run --scope identity
→AS-REP roast · 3 accounts
→Kerberoast · svc_sql cracked
→NTLM relay → DCSync
✓Domain Admin, proven

IT/OT boundary: Active Directory, MES/ERP, historians, segmentation

From an assumed-breach foothold on the office network: identity attacks, lateral movement to engineering hosts, MES and ERP application testing, historian front ends, and the question that matters: which control-network addresses are reachable from where. Reachability is observed, never exercised.

cloud, pipelines, firmware
Attack surfaceexposure

Cloud, CI/CD and connected products

Cloud tenants and IIoT platforms, Kubernetes clusters, pipeline secrets and artefact registries of your industrial software, and the firmware of connected products you ship, analysed on a bench, never on a running line. The infrastructure graph ties the three shapes together.

S.07How an engagement works

From order to report, in five steps.

A process designed to be simple for the client and rigorous on the security side.

01
Describe your target

A guided form: target type, scope and objectives.

How the engine works

S.08Evidence & reporting
Concrete, actionable deliverables.

Not just an automated scan: a structured, validated and debriefed audit.

ranked
FindingsCVSS
SQL injection9.8
SSRF to metadata9.1
Broken access control8.7
JWT signature bypass7.5
Path traversal6.9

Detailed pentest report

Vulnerabilities ranked by severity, technical evidence, business impact and prioritized remediation guidance.

email + OTP
New engagement
Targetapp.acme.test
Scopeweb · API · cloud
Window5 business days
Flat rate€799

Secure client space

Access by email and OTP code. Contractual documents, report and exchanges centralized, available whenever you need them.

video call
Attack surfaceexposure

Debrief meeting

A video call with an expert to walk through the findings, answer questions and guide you on the fixes.

S.09Where your data goes
Your data stays on your side of the line.

The Privacy Gateway tokenizes every sensitive value (IPs, hostnames, URLs, emails, credentials, internal paths) on your machine before anything reaches the model, and rehydrates it locally. Self-host the whole engine with a local LLM, or let our experts run the managed engagement: in both cases the evidence stays in a space you control.

S.10Regulatory context
NIS2 by family: manufacturing, energy, water, transport

NIS2 names these sectors in its Annexes; the rule that decides whether a given company is in scope is the same for all of them. An entity of a listed type is in scope when it is at least a medium-sized enterprise: 50 staff or more, or an annual turnover AND balance-sheet total above €10 M; essential entities are the large ones, 250 staff or more, or turnover above €50 M and balance sheet above €43 M; plus the size-independent cases of Article 2(2) and Article 3. Annex I entities above the medium ceilings are essential; medium-sized Annex I entities and all Annex II entities are important. In France the transposition law is not in force: the bill is scheduled for public session at the Assemblée nationale on 7 October 2026, and ANSSI offers pre-registration on messervices.cyber.gouv.fr/nis2.

Manufacturing: Annex II, point 5, and Annex I for pharma

Annex II lists as “other critical sectors” the manufacture of “(a) medical devices and in vitro diagnostic medical devices” (Reg. 2017/745 and 2017/746), “(b) computer, electronic and optical products” (NACE Rev. 2 section C division 26), “(c) electrical equipment” (division 27), “(d) machinery and equipment n.e.c.” (division 28), “(e) motor vehicles, trailers and semi-trailers” (division 29) and “(f) other transport equipment” (division 30). Manufacturers of basic pharmaceutical products (NACE C 21) and of crisis-critical medical devices (Reg. 2022/123 Art. 22) are Annex I, point 5. Food, textiles, metals and plastics are not listed as manufacturing.

Energy: Annex I, point 1

Electricity undertakings carrying out supply, distribution and transmission system operators, producers, nominated electricity market operators, market participants providing aggregation, demand response or storage, operators of recharging points; operators of district heating or cooling; oil pipelines, production, refining, storage and central stockholding; gas supply, DSOs, TSOs, storage and LNG; hydrogen production, storage and transmission. The Network Code on Cybersecurity for electricity (Reg. 2024/1366) adds sector rules, and designated operators also fall under the CER Directive and, in France, the OIV/SAIV regime of the loi de programmation militaire.

Drinking water and waste water: Annex I, points 6 and 7

“Suppliers and distributors of water intended for human consumption” (Dir. 2020/2184), excluding distributors for which it is a non-essential part of distributing other goods, and “undertakings collecting, disposing of or treating urban, domestic or industrial waste water” (Dir. 91/271/EEC), excluding those for which it is non-essential. Article 2(2)(b) and (c) let a Member State bring in an operator of any size when it is the sole provider of an essential service or when a disruption could have a significant impact on public health.

Transport: Annex I, point 2

Air: commercial air carriers, airport managing bodies and airports including core TEN-T airports, air traffic control providers. Rail: infrastructure managers and railway undertakings including operators of service facilities. Water: inland, sea and coastal passenger and freight water transport companies, port managing bodies and port facilities, vessel traffic services. Road: road authorities responsible for traffic management and operators of intelligent transport systems. Logistics and trucking companies are not named.

Darkmoon does not certify compliance. This section is general information, not legal advice, and reflects the texts as of 4 October 2026, before the French transposition law is promulgated.

S.11Use case
A machinery manufacturer with three plants and a connected product line

The CISO of a machinery group (NACE C28) has two questions: can the integrators' remote-maintenance access reach the engineering workstations, and does the CI/CD of the connected product expose the update channel. The scoping call fixes the frame: external surface and vendor VPNs in full, the office Active Directory from an assumed-breach foothold, control-network ranges declared and observed passively, the firmware of the connected product analysed on a bench, testing windows outside production shifts.

Outcome

A report ranked by severity with the evidence of each step, an infrastructure graph showing the path from a reused integrator credential to the engineering VLAN and the one from a pipeline token to the artefact registry, a debrief with the CISO and the plant automation lead, and a fix list the group can hand to its integrators. Nothing on the line was touched; the group now knows how far an attacker would get before reaching it.

Pentest on Demand
€799/ engagement
  • Full penetration test on the defined scope
  • Legal framework and authorizations included
  • Detailed report with evidence and recommendations
  • Secure client space with OTP access
  • Video debrief meeting with an expert
  • Personalized scoping by our team
S.12Pricing

A clear flat rate, shown upfront.

The price is known before payment. No quote, no surprise. Indicative price, adjusted to the final scope. If the scoping call changes the scope and the price, you are told before anything starts.

Legal framework & authorizations included

S.13Frequently asked
What a plant manager or OT security lead asks first.

Do you do OT penetration testing on our PLCs and SCADA?

No. Darkmoon never fuzzes a PLC, RTU or safety-system protocol and never sends commands to a process, in any edition. What it does is test the IT/OT boundary: exposed HMIs and web consoles, remote-maintenance VPNs, MES and ERP, historians' web front ends, engineering hosts, cloud and CI/CD, and observe which control-network addresses are reachable from where.

Can the test stop the line?

The framework you sign declares the OT ranges, and the scoping call sets them to passive observation or excludes them; testing windows avoid production shifts. Tool execution is gatekept by an MCP gateway with a build-enforced allow-list, so the model never gets a shell. In the managed engagement ASC-IT's experts supervise the run end to end.

Are we in scope of NIS2?

It depends on your Annex type, your size and national identification. Manufacturers in NACE divisions 26 to 30 and medical-device manufacturers are Annex II; pharma, energy, water and transport operators are Annex I; the size rule starts at 50 staff or €10 M turnover and balance sheet. Use ANSSI's self-assessment on messervices.cyber.gouv.fr/nis2 and your legal team; Darkmoon does not decide that for you.

We are an OIV or operate a SIIV. Does this count as an audit under that regime?

No. The French OIV/SAIV regime under the loi de programmation militaire has its own supervision by ANSSI and its own rules; Darkmoon's results are technical evidence for your own security programme, not an audit under that regime. We state the boundary rather than blur it.

Does Darkmoon assess our IEC 62443 zones and conduits?

Darkmoon does not assess conformity to IEC 62443 or any other standard, and it does not certify compliance. What it can show is whether the boundaries you drew hold from the IT side: whether an engineering host is reachable from the office domain, whether a vendor VPN lands in the wrong zone, whether a historian exposes a write path. That is evidence for your own assessment.

Our plant has no internet access. Can it run offline?

Yes. The Community edition is self-hosted by default and works with a local LLM via Ollama or llama.cpp, so nothing leaves the site. The Privacy Gateway tokenizes IPs, hostnames, URLs and credentials before anything reaches the model even when a cloud model is used. Pro adds appliance mode and a hardened sealed runtime for exactly this situation.

How is a multi-plant group priced?

The managed engagement is shown at a flat €799, indicative and adjusted to the final scope during the scoping call. A group with several plants, vendor networks and a product pipeline will typically be split into several scopes. Partners and MSSPs serving industrial clients can also license the platform through the partner program (1 to 100 machines per key).

What do we need to provide?

A written authorization for the targets in scope (the legal framework you sign at order time), the URLs, hostnames or network ranges to test, test accounts where authenticated testing matters, and a contact for the scoping call. Our experts confirm the scope and the constraints with you before the engagement starts.

Can we share the report with our insurer, clients or auditors?

Yes. The report is yours. It documents each finding with its evidence, severity and remediation guidance, so it can be handed to a cyber-insurer, a client's procurement team or an auditor as a dated, factual description of what was found. It is evidence, not a certification.

What happens after the report?

You get a prioritised fix list with the evidence for each finding, a debrief call to walk through it, and the option to retest once the fixes are in. Teams that self-host can schedule recurring campaigns (Pro) so the same checks run after each change; the Pro remediation agent can also open sandbox-validated fix pull requests for your developers to review.

S.14Related
Go deeper

S.15Next
Find the path to the plant before someone else walks it.

Describe your HMIs, vendor VPNs, MES and tenants, declare the OT ranges, sign the framework online and get an evidence-backed report with a debrief. The controllers stay untouched; the way to them gets mapped.