Darkmoon is an autonomous penetration testing platform designed for security professionals who demand more than automated scanners can offer. It categorizes itself as an offensive security conductor, not a simple vulnerability scanner. The platform orchestrates a full campaign using 18 AI agents that reason about the target, model the attack surface, and dispatch the right tools. It is ideal for professional pentesters, security teams, incident responders, and managed security service providers (MSSPs) seeking continuous, repeatable, and validated security testing. The core value proposition is the ability to run comprehensive pentests autonomously, reducing manual effort while producing evidence-backed findings ready for compliance and remediation.
Traditional penetration testing is slow, manual, and inconsistent, often leaving gaps that attackers exploit. Security teams struggle to keep up with rapid infrastructure changes, and vulnerability scanners produce noisy results without context. Darkmoon solves this by automating the entire offensive workflow, from reconnaissance to exploitation, with AI-driven reasoning that validates findings using real payloads. This matters because it drastically reduces the time from discovery to remediation, ensures thorough coverage of web, API, Kubernetes, and Active Directory attack surfaces, and delivers structured reports with CVSS 3.1 scoring and MITRE ATT&CK mapping. Organizations can run continuous campaigns instead of periodic assessments, catching critical vulnerabilities before they are exploited.
Darkmoon's core engine uses a master agent that detects 14 technology signals from the target. It then routes the campaign to the right specialist agents, operating sequentially or in parallel with cascade depth capped at three levels to prevent runaway recursion. These specialists cover web application exploitation including SQLi, XSS, SSRF, and RCE, Kubernetes attack chains such as RBAC escalation and node escape, and Active Directory takeover with Kerberoasting, DCSync, and Golden Tickets. Each agent validates findings with actual payloads, not just signatures. This feature automates the decision-making of a senior pentester, adapting the campaign strategy based on real-time discoveries for a thorough, methodical attack simulation covering the entire attack surface.
The live SSE stream provides real-time visibility into every finding, infrastructure node, and agent event as they happen. Darkmoon's dashboard displays a live command center with statistics on projects, targets, campaigns, and vulnerabilities, including severity breakdowns. The infrastructure map graphically shows every host, path, and vulnerability, allowing teams to visualize the attack surface. The streaming feature matters because it enables immediate response to critical findings, such as SQL injection on a login endpoint. Security teams can watch the campaign unfold and intervene if necessary, or simply monitor progress. This real-time transparency builds trust and allows for faster decision-making.
admin
Darkmoon exports reports in ISO 27001, HackerOne, and Bugcrowd formats, both Markdown and branded, password-protected PDF with CVSS 3.1 scoring and MITRE ATT&CK mapping. This ensures findings are immediately usable for compliance or submission to bug bounty programs. The platform's runtime is hardened with AES-256-GCM sealed storage, hardware-bound licensing, a binary integrity watchdog that re-verifies SHA-256 hashes every two seconds, and anti-tamper detection for debuggers like gdb and frida. These security features protect the integrity of the platform and the confidentiality of findings, making it safe to run against production environments. The sealed runtime guarantees that agents and workflows are encrypted at rest, and any tampering triggers an immediate zeroize.
Darkmoon operates on a unique architecture where the AI agent plans the attack but never gets shell access. An MCP gateway gatekeeps every tool call, ensuring safe execution. The open-source engine is freely available on GitHub under GPLv3, with a Pro version adding a hardened sealed runtime and managed command center. The workflow begins by specifying a target (e.g., ./darkmoon.sh "TARGET: acme.test"), then the master agent performs reconnaissance to detect tech signals, dispatches specialist agents, and streams results live to the dashboard. The entire campaign is logged and can be replayed. This approach combines the autonomy of AI with the control of manual pentesting, giving users validated findings without the overhead of manual tool chaining.
A typical use case is a security team conducting a weekly autonomous pentest on their staging environment. They set up a campaign targeting an internal domain, and within 30 minutes Darkmoon discovers critical SQL injection, RCE vulnerabilities, and misconfigured Kubernetes RBAC. The team receives an infrastructure map showing every compromised node. Another scenario is an MSSP reselling Darkmoon to clients; they use the partner program to run campaigns under their own brand, delivering branded reports. For bug bounty hunters, Darkmoon can automate reconnaissance and validation, surfacing unique attack paths. Outcomes include reduced manual effort by 80%, faster remediation cycles, and compliance with standards like ISO 27001 through structured evidence. The platform replaces periodic external pentests with continuous, on-demand testing.
Darkmoon targets professional penetration testers, security engineers, DevOps teams, and MSSPs. It runs on Linux via Docker, with a community edition that is fully open source and free. Pro pricing starts at €149 per month billed annually, including a hardened runtime, all report formats, and priority support. Custom plans are available for enterprises and resellers. The tech stack includes over 80 tools like subfinder, httpx, naabu, nuclei, sqlmap, bloodhound, and kubescape, all coordinated by AI. The takeaway: Darkmoon delivers autonomous, evidence-backed penetration testing that scales from individual pentesters to large enterprises, replacing manual processes with intelligent automation.
Professional penetration testers, security engineers, DevSecOps teams, managed security service providers (MSSPs), enterprises requiring continuous security testing, and bug bounty hunters. The platform is also suitable for compliance officers needing evidence-backed reports for audits and for resellers who want to offer offensive security services under their own brand. It serves organizations of all sizes, from individual security researchers to large enterprises with complex hybrid infrastructures including Kubernetes and Active Directory environments.