Darkmoon is an autonomous penetration testing platform purpose-built for security teams that demand comprehensive, evidence-backed findings without the overhead of manual orchestration. As an offensive security automation tool, it bridges the gap between static vulnerability scanners and full-scale manual penetration tests. The platform is designed for professional pentesters, security engineers, and MSSPs who need to validate attack surfaces rapidly. Its core value lies in replacing one-pass signature scanning with an intelligent, autonomous conductor that reasons about the target, models the attack surface, and dispatches the right specialist agents. With 18 AI agents and over 80 integrated tools working in concert, Darkmoon runs a complete offensive campaign from reconnaissance to exploitation and reporting, all streamed live to a command center dashboard. This transforms the way teams approach security testing, turning weeks of manual effort into hours of automated, validated results.
The primary pain point Darkmoon addresses is the slow, labor-intensive nature of traditional penetration testing. Manual pentests are expensive, require deep specialization, and often produce results that are outdated by the time the report is delivered. Vulnerability scanners, on the other hand, generate high false-positive rates and lack the context to chain attack paths or validate findings with real payloads. Darkmoon solves this by automating the entire pentest workflow: it discovers the technology stack, dispatches domain-specific agents for web, API, Kubernetes, and Active Directory environments, and validates each finding with working exploits. The result is a dramatically faster cycle from identification to remediation, with validated evidence that can be directly acted upon. For organizations that need continuous assurance, Darkmoon provides a repeatable, consistent methodology that fits into DevOps pipelines.
Darkmoon's core engine is its multi-agent dispatch system, which detects up to 14 technology signals from the target during reconnaissance. Based on these signals, the master agent routes the campaign to the right specialist agents — for web, infrastructure, or identity attacks — executing them sequentially or in parallel. Cascade depth is capped at three levels to prevent runaway recursion, ensuring that each campaign remains focused and efficient. This orchestration is not a simple script; the AI reasons about the attack surface and decides the optimal sequence of actions. For example, if a target runs WordPress and has an exposed admin panel, the WordPress agent is dispatched first, followed by web exploitation agents. This intelligent routing means no manual pivoting is needed; the platform automatically adapts to the target's unique configuration.
admin
Darkmoon is built like a vault with multiple layers of runtime security. The platform operates in a sealed runtime with AES-256-GCM encrypted storage at rest, where agents and workflows are encrypted and keys derive from the hardware fingerprint and license, resealed every 30 seconds. Hardware-bound licensing ensures that the deployment ID cannot be spoofed, as the machine code derives from MAC address and CPU model. A binary integrity watchdog re-verifies SHA-256 hashes of critical binaries every two seconds, and any tampering triggers an immediate zeroize. Continuous scanning detects debuggers and tracers like gdb, strace, frida, and lldb; any tracer triggers a breach and full state zeroize. The process runs unprivileged with read-only rootfs, tmpfs writable paths, seccomp, and no-new-privileges, and all secrets are scrubbed from logs. This ensures that even if the container is compromised, the attacker cannot extract credentials or persistence.
Darkmoon provides publication-ready reports in ISO 27001, HackerOne, and Bugcrowd formats, including Markdown and branded, password-protected PDF with CVSS 3.1 scoring and MITRE ATT&CK mapping. The live SSE dashboard streams every finding, infrastructure node, and agent event the instant it happens, giving teams real-time visibility into the campaign's progress. The infrastructure map visualizes all hosts, connections, and vulnerabilities by severity, allowing security analysts to understand the attack surface at a glance. The platform integrates over 80 tools, including subfinder, httpx, naabu, katana, nuclei, ffuf, wpscan, sqlmap, hydra, hashcat, netexec, bloodhound, impacket, mimikatz, kubectl, kubescape, and more, all coordinated by the AI. This integration eliminates the need to manually chain tools; Darkmoon handles the coordination and validation.
Darkmoon's workflow begins when a user defines a target (a domain, IP range, or URL) and launches a campaign. The master agent performs reconnaissance, detecting up to 14 technology signals such as web frameworks, Kubernetes clusters, or Active Directory servers. Based on these signals, it dispatches specialist agents — for web exploitation, Kubernetes attack chains, or Active Directory takeover — each following a defined phase model. The agents execute actions like SQLi, XSS, SSRF, IDOR, RCE, RBAC escalation, kerberoasting, and more, with cascade control ensuring depth is limited. All events stream live via SSE to the command center dashboard, where the team can see vulnerabilities by severity, infrastructure map, and agent event stream. At the end, the platform produces a structured, evidence-backed report. The entire process is automated, from start to finish, requiring no manual intervention after the initial target specification.
A typical use case is a security team running a campaign against their production web application stack. Within 30 minutes, Darkmoon discovers 57 vulnerabilities across the stack, including critical SQLi on login endpoints, and maps the entire infrastructure. The team gets a report with CVSS scores, MITRE ATT&CK mappings, and validated payloads, ready for developer remediation. Another scenario: an MSSP uses Darkmoon to run monthly penetration tests for multiple clients, scaling their offering without hiring additional pentesters. The platform's managed service option allows clients to order a pentest on demand, where Darkmoon experts run the engagement and deliver a debriefed report. For DevOps teams, integrating Darkmoon into CI/CD pipelines provides continuous assurance against regressions. The outcome is consistently validated findings, reduced time-to-remediation, and a clear audit trail.
Darkmoon is designed for professional penetration testers, security teams, MSSPs, and resellers. It is open source under GPLv3 with a free Community edition, making it accessible to individual pentesters and small teams. The Pro plan at €149/month (billed annually) adds hardened runtime, managed command center, all report formats, and priority support. The Custom plan for enterprises and MSSPs includes multi-seat workspaces and dedicated onboarding. The platform runs as a Docker container on the user's infrastructure, requiring no cloud dependency. A managed Pentest on Demand service is also available at €799/engagement for those who prefer not to self-host. In summary, Darkmoon replaces static pentests with autonomous security testing, delivering live visibility and validated evidence the same day. It empowers security teams to move from periodic manual tests to continuous, automated assurance.
Professional penetration testers, security engineers, DevOps teams, MSSPs, and resellers who need an autonomous alternative to manual pentesting. Suitable for organizations requiring continuous validated testing of web applications, APIs, Kubernetes clusters, and Active Directory environments. Also ideal for open-source communities and small teams that want a free, self-hosted community edition with full agent capabilities.