S.01MSP and MSSP

Your RMM console reaches every client. So does an attacker.

Your RMM and PSA consoles, delegated admin rights on client tenants, backup servers and VPN edge reach every client at once, and NIS2 Annex I point 9 names managed and managed security service providers directly: Darkmoon tests that estate the way an attacker would and keeps the evidence of each hop. Once your own house is tested, the partner program lets you resell and operate the same engine for your clients, with keys covering 1 to 100 machines each.

1 to 100
machines per partner licence key
50
specialist AI agents, 142 tools
OTP
secure client space for the report
Local
self-hosted option, model on your side

S.03Technology & SaaS
Why MSPs and MSSPs are a target of choice.

An MSP is the shortest path into dozens of networks at once. CERT-FR cites, via CERT-Bund, the October 2023 Akira ransomware attack on an IT provider serving 72 German municipalities and 20,000 workstations, with 1.7 million inhabitants affected and recovery still incomplete months later. ANSSI's 2025 panorama notes data exfiltrations that followed the compromise of a service provider.

ClientsBilling · Stripe
Acme Corp3 licences
Nordic SOC12 licences
Blue Harbor1 licence
Margin this month−35 %

One console, every client

The RMM or PSA platform that lets a technician push a script to a thousand endpoints does the same for an attacker holding one technician's session. Multi-tenant tooling turns one compromise into a campaign.

FindingsCVSS
SQL injection9.8
SSRF to metadata9.1
Broken access control8.7
JWT signature bypass7.5
Path traversal6.9

Standing privileged access

Domain admin, Global Administrator through delegated partner relationships, hypervisor root and backup console credentials sit in a documentation platform or a password vault that every technician can open.

$darkmoon run --scope identity
→AS-REP roast · 3 accounts
→Kerberoast · svc_sql cracked
→NTLM relay → DCSync
✓Domain Admin, proven

Edge devices as the front door

VPN concentrators, firewalls and jump hosts exposed for remote support are the vector ANSSI reports as heavily targeted; a missed patch cycle on one appliance is an entry into the clients behind it.

Attack surfaceexposure

Clients now ask for your evidence

NIS2 entities must address supply-chain security (Article 21(2)(d)) and are writing it into provider contracts; your own position under Annex I point 9 brings the same question from the regulator's side.

S.04Attack surface
The attack surface of a managed service provider.

Six families of systems a Darkmoon campaign enumerates and attacks on an MSP's estate, each of them a door to several clients at once.

RMM / PSA
Remote monitoring, management and ticketing

Consoles such as ConnectWise, Datto, NinjaOne or Kaseya and the PSA behind them: exposed logins without MFA, API keys in scripts, agent deployment paths, credentials and attachments inside tickets.

Privileged access
Credential vaults and documentation platforms

Shared administrator accounts, documentation tools holding client passwords and network diagrams, privileged-access workflows, service accounts reused across tenants.

VPN / jump hosts
Remote-access edge

SSL VPN appliances, firewalls with management interfaces reachable from the internet, bastion and jump hosts, RDP gateways, site-to-site tunnels into client networks.

Microsoft 365
Delegated administration (GDAP) and Entra ID

Granular delegated admin relationships, partner tenant roles, conditional access gaps, legacy authentication, OAuth applications with excessive consent across client tenants.

Backup
Backup and recovery consoles

Veeam or cloud backup management servers, immutability settings, repository credentials, the restore paths an intruder deletes first and a client needs most.

Client portal
Client-facing portals and APIs

Self-service portals, status pages, invoicing and asset inventories exposed to clients, SSO between your tenant and theirs, and the APIs your own integrations consume.

S.05Attack paths

From one technician's phish to every client's domain.

Four chains Darkmoon's agents attempt on an MSP estate. Each hop is executed and documented; the infrastructure graph shows which client networks a single credential reaches.

01
Phished technician to RMM script push

A technician's session on the RMM console without phishing-resistant MFA lets the agent deploy a script to every managed endpoint of a client group, the same mechanism a ransomware operator uses.

How the engine works

S.06What Darkmoon tests
What Darkmoon tests for an MSP, on your estate and on your clients'.

Run campaigns on your own infrastructure and, under each client's written authorization, on theirs. 50 specialist agents and 142 tools behind a build-enforced allow-list; the model never gets a shell.

RMM, GDAP, AD
FindingsCVSS
SQL injection9.8
SSRF to metadata9.1
Broken access control8.7
JWT signature bypass7.5
Path traversal6.9

Privileged paths across tenants

Active Directory and Entra ID, delegated partner roles, RMM and PSA consoles, credential vaults: the agents look for the shortest path from one foothold to several clients and keep the evidence of each hop.

VPN, jump hosts, k8s
$darkmoon run --scope identity
→AS-REP roast · 3 accounts
→Kerberoast · svc_sql cracked
→NTLM relay → DCSync
✓Domain Admin, proven

Edge, remote access and Kubernetes

VPN and firewall appliances, bastions, RDP gateways, exposed management planes and the clusters hosting your tooling, mapped in the infrastructure graph of hosts, paths and relationships.

web / API / backup
Attack surfaceexposure

Client portals, APIs and backup consoles

Portals and APIs you expose to clients, SSO between tenants, backup management servers and their repositories; findings qualified EXPLOITED, CONFIRMED or UNCONFIRMED by an adversarial rubric.

S.07How an engagement works

From order to report, in five steps.

A process designed to be simple for the client and rigorous on the security side.

01
Describe your target

A guided form: target type, scope and objectives.

How the engine works

S.08Evidence & reporting
Concrete, actionable deliverables.

Not just an automated scan: a structured, validated and debriefed audit.

ranked
FindingsCVSS
SQL injection9.8
SSRF to metadata9.1
Broken access control8.7
JWT signature bypass7.5
Path traversal6.9

Detailed pentest report

Vulnerabilities ranked by severity, technical evidence, business impact and prioritized remediation guidance.

email + OTP
darkmoon-licence.dmeDocker
LicencePro · annual
Machine code7F3A-…-C21E
Seats1 node
Statussealed ✓

Secure client space

Access by email and OTP code. Contractual documents, report and exchanges centralized, available whenever you need them.

video call
Attack surfaceexposure

Debrief meeting

A video call with an expert to walk through the findings, answer questions and guide you on the fixes.

S.09Where your data goes
Your clients' data stays in their network, and yours in yours.

Darkmoon runs on a machine inside the perimeter it tests: the Privacy Gateway tokenizes IPs, hostnames, URLs, emails, credentials and internal paths before anything reaches the model, a local LLM via Ollama or llama.cpp keeps it entirely on premises, and the Pro runtime stores evidence in AES-256 under a hardware-bound licence. Towards your SOC tooling only safe metadata travels: severity, status, ids, MITRE tags and timestamps.

S.10Regulatory context
NIS2 names managed service providers directly.

Unlike most of your clients' sectors, yours appears in NIS2 by name. The GDPR adds processor duties (Article 28), your contracts add the flow-down from regulated clients, and the Implementing Regulation details the technical requirements. What follows is the picture as of 4 October 2026.

Annex I point 9: ICT service management (business-to-business)

NIS2 Annex I, sector 9 'ICT service management (business-to-business)', lists 'Managed service providers' and 'Managed security service providers' among the sectors of high criticality. An entity of that type is in scope when it is at least a medium-sized enterprise: 50 staff or more, or an annual turnover and balance-sheet total above €10 M; essential entities are the large ones, 250 staff or more, or turnover above €50 M and balance sheet above €43 M; plus the size-independent cases of Article 2(2) and Article 3. Medium-sized MSPs are important entities, large ones essential entities.

Implementing Regulation (EU) 2024/2690

For eleven categories of entities, including managed service providers and managed security service providers, Commission Implementing Regulation (EU) 2024/2690 details the technical and methodological requirements of the Article 21(2) risk-management measures. It is the text your security policies, testing procedures and incident handling will be read against.

Articles 21 and 23: where testing and notification sit

Article 21(2)(f) requires policies and procedures to assess the effectiveness of cybersecurity risk-management measures; a validated penetration test is one way to produce that evidence. Article 21(2)(e) covers vulnerability handling and disclosure, and Article 21(2)(d) supply-chain security, which your clients flow down to you. Article 23 sets the incident timelines: early warning within 24 hours, notification within 72 hours, final report within one month. The Directive names no test type or frequency.

France: transposition not yet in force

The French bill relatif à la résilience des infrastructures critiques et au renforcement de la cybersécurité was adopted by the Sénat in first reading on 12 March 2025 and is scheduled for public session at the Assemblée nationale on 7 October 2026; it is not promulgated as of 4 October 2026. ANSSI already offers pre-registration and an eligibility self-test on messervices.cyber.gouv.fr/nis2, published the Référentiel Cyber France (ReCyF) on 17 March 2026, and has announced a progressive, three-year approach to sanctions.

Informational summary, not legal advice: whether you are an essential or important entity depends on your Annex I type, your size under Recommendation 2003/361/EC and national identification; use ANSSI's self-assessment and your counsel. Darkmoon does not certify compliance. Status as of 4 October 2026.

S.11Use case
An MSSP adds autonomous pentest to its service catalogue.

A managed security provider serving SMEs and local authorities joins the partner program, is approved within about two business days and buys annual keys labelled per client from its dashboard. Each client runs ./install.sh KEY on a machine inside its own network, under a signed test authorization; the MSSP schedules recurring campaigns from the Pro dashboard, delivers branded PDF reports and pushes safe-field posture data into the Grafana and Splunk views its SOC already watches. Its own estate, RMM console, delegated admin relationships and VPN edge, is tested the same way before a client or a regulator asks.

Outcome

A recurring pentest line in the catalogue with no licence server or billing to build, evidence-backed reports per client, and the MSSP's own Annex I exposure assessed with the same engine. Compliance remains the client's and the MSSP's organisational responsibility; Darkmoon supplies the test and the proof.

S.12Run it yourself
Open source, self-hosted, on a local model if you want.

The Community edition is GPLv3: clone it, install it, point it at a target you are authorized to test. Pro adds the dashboard, scheduler, branded reports and the remediation agent. The managed engagement stays available when you would rather hand it to us.

S.13Frequently asked
What an MSP owner asks first.

Is my MSP or MSSP in scope of NIS2?

Managed service providers and managed security service providers are listed in NIS2 Annex I, sector 9 'ICT service management (business-to-business)'. You are in scope when you are at least a medium-sized enterprise (50 staff or more, or turnover and balance sheet above €10 M) or when a size-independent case of Article 2(2) applies. In France the transposition law is not in force as of 4 October 2026, and ANSSI offers a self-assessment and pre-registration.

What does Implementing Regulation 2024/2690 change for an MSP?

It details, for MSPs and MSSPs among eleven categories, the technical and methodological requirements behind the Article 21(2) measures: policies, incident handling, business continuity, supply-chain security, assessment of effectiveness and the rest of the list. A reproducible penetration test with evidence is one way to document that assessment; it is not a certification, and Darkmoon does not certify compliance.

Can I run Darkmoon against my clients' environments?

Only with each client's written authorization, which the partner model expects you to hold as their provider. A licence key covers 1 to 100 machines and keys are labelled per client, so one key per tenant is the usual layout. If you would rather have ASC-IT's experts run a specific engagement, Pentest on Demand includes the legal framework and authorization flow.

What leaves the client's host into Splunk, Grafana or n8n?

Only safe metadata: severity, status, identifiers, MITRE ATT&CK tags and timestamps. Evidence bodies, secrets and raw requests or responses never cross the API, the webhooks or the event stream. The Splunk integration works with the Community CLI; the n8n node and the Grafana datasource consume the Pro REST API.

How does the partner program work: pricing, branding and licensing?

You apply with your company registration number, are reviewed within about two business days, then buy keys from your dashboard at the partner price and resell at a price you set; each key is bound to one machine's hardware fingerprint and can be labelled, suspended or revoked from the dashboard. Pro produces branded PDF and web reports, while the product itself runs Darkmoon-branded in the client container at this stage. See the partner program page for the pricing tiers, the white-label status and the full terms.

What happens after the report?

You get a prioritised fix list with the evidence for each finding, a debrief call to walk through it, and the option to retest once the fixes are in. Teams that self-host can schedule recurring campaigns (Pro) so the same checks run after each change; the Pro remediation agent can also open sandbox-validated fix pull requests for your developers to review.

S.14Related
Go deeper

S.15Next
Put autonomous pentest in your catalogue this quarter.

Apply to the partner program, get your first keys, and test your own RMM and edge before a client or a regulator asks.