S.01Integrations

Darkmoon fits where your team already works

One autonomous pentest engine, reachable from your IDE, your pipeline, your automation platform and your SOC. Each surface auto-detects its edition: the community CLI reads your local JSON report, and the paid Pro tier adds the live REST API, streaming and remediation.

9
Surfaces: eight platforms and one SDK
6
Live marketplace and registry listings
7
Run on the open-source CLI
9
Video tutorials, one per surface
Darkmoon everywhere

Runs where your team already works.

GitHub Action · CI/CD · OSS + ProGitHub Action · OSS + Pro
GitLab CI/CD component · CI/CD · OSS + ProGitLab CI/CD component · OSS + Pro
Jenkins plugin · CI/CD · OSS + ProJenkins plugin · OSS + Pro
VS Code extension · IDE · OSS + ProVS Code extension · OSS + Pro
JetBrains plugin · IDE · OSS + ProJetBrains plugin · OSS + Pro
n8n community node · Automation · Pro onlyn8n community node · Pro only
Foundation SDK / CLI · SDK · OSS + ProFoundation SDK / CLI · OSS + Pro

The same open-source engine, wired into your IDE, your CI/CD, your automation and your SecOps stack. Each surface auto-detects its edition: the community CLI runs on your local JSON report; the paid Pro tier adds the live REST API, streaming and remediation.

S.04Where it plugs in
Five places, one engine

IDE, CI/CD, automation, observability and the SDK underneath them all. Pick the category that matches how your team already works.

S.05Integration surface
Eight platforms and one SDK

Every link below is verified. Where a marketplace listing is still in review, we point you at the repository releases instead of a page that would 404.

CI/CD · OSS + Pro

GitHub Action

Run a pentest in your pipeline, gate the build on exploited findings, and attach the report to the run.

uses: ASCIT31/darkmoon-action@v0.1.0
Live on GitHub Marketplace
CI/CD · OSS + Pro

GitLab CI/CD component

A catalogue component that runs the scan and emits GitLab Code-Quality and SAST reports.

component: $CI_SERVER_FQDN/<ns>/darkmoon/scan@1.0.0
Live on the CI/CD Catalog
CI/CD · OSS + Pro

Jenkins plugin

A pipeline step (darkmoonScan) that publishes SARIF into Warnings-NG. Update Center listing pending.

darkmoonScan step · SARIF 2.1.0 via Warnings-NG
Install the .hpi from Releases
IDE · OSS + Pro

VS Code extension

Browse findings and launch a campaign from the editor; Pro adds live status and the dashboard.

Darkmoon.darkmoon-vscode
Live on the VS Code Marketplace
IDE · OSS + Pro

JetBrains plugin

Same browse/launch flow across the IntelliJ family; Pro adds streaming and remediation review.

fr.ascit.darkmoon
Live on the JetBrains Marketplace
Automation · Pro only

n8n community node

Trigger campaigns and read Finding / Retest / Metric / Webhook operations from a workflow. Consumes the Pro REST API.

n8n-nodes-darkmoon
Published on npm
Observability · Pro only

Grafana app

Security-posture dashboards over the Pro REST API. grafana.com catalog submission pending.

gpx_datasource + dashboards (self-host)
Install from Releases
Observability · OSS + Pro

Splunk app

OSS exports safe-field JSON to HEC; Pro adds REST pull and a 'Send to Darkmoon' alert action. Splunkbase approval pending.

darkmoon --export FILE → HEC (safe fields only)
Install the .tar.gz from Releases
SDK · OSS + Pro

Foundation SDK / CLI

The shared client every integration builds on: an oss-local backend (local JSON + darkmoon.sh) and a pro-http backend (full /api/v1).

@darkmoon_ai/client · bin darkmoon-ci
Published on npm

S.06Editions
OSS or Pro, and what actually leaves the host

OSS + Pro
$darkmoon run --scope identity
→AS-REP roast · 3 accounts
→Kerberoast · svc_sql cracked
→NTLM relay → DCSync
✓Domain Admin, proven

Community (OSS CLI)

Every "OSS + Pro" surface degrades to the local engine: it reads the JSON report your darkmoon.sh / darkmoon-ci run writes to a bind-mounted data dir, and can browse, launch and gate a build without any network. No dashboard, no streaming, no remediation.

Pro only
Attack surfaceexposure

Pro (REST /api/v1)

The paid tier adds live SSE streaming, the hosted dashboard, remediation→PR (always UI-gated, never auto-merged), the scheduler and HMAC-signed webhooks. The n8n node and the shipped Grafana datasource are REST consumers, so they are Pro only.

Every integration
FindingsCVSS
SQL injection9.8
SSRF to metadata9.1
Broken access control8.7
JWT signature bypass7.5
Path traversal6.9

What leaves the host

Across every integration, only safe metadata leaves the host, severity, status, ids, MITRE tags and timestamps. Evidence bodies, secrets and raw requests/responses never cross the API, the webhooks or the event stream.

S.07Next
Pick the surface that fits your stack

Automation-first, CI-first, IDE-first or SOC-first, the same open-source engine underneath, with an optional Pro control plane.