EveryDev.ai
Subscribe
Home
Tools

2,885+ AI tools

  • New
  • Trending
  • Featured
  • Compare
  • Arena
Categories
  • Agents1815
  • Coding1295
  • Infrastructure600
  • Marketing467
  • Projects433
  • Research403
  • Analytics351
  • Design338
  • Security243
  • MCP242
  • Testing238
  • Data230
  • Integration178
  • Prompts160
  • Learning159
  • Communication154
  • Extensions150
  • Voice130
  • Commerce125
  • DevOps108
  • Web80
  • Finance21
AI Tools by Topic
  • AI Coding Assistants
  • Agent Frameworks
  • MCP Servers
  • AI Prompt Tools
  • Vibe Coding Tools
  • AI Design Tools
  • AI Database Tools
  • AI Website Builders
  • AI Testing Tools
  • LLM Evaluations
Follow Us
  • X / Twitter
  • LinkedIn
  • Reddit
  • Discord
  • Threads
  • Bluesky
  • Mastodon
  • YouTube
  • GitHub
  • Instagram
Get Started
  • About
  • Editorial Standards
  • Corrections & Disclosures
  • Community Guidelines
  • Advertise
  • Contact Us
  • Newsletter
  • Submit a Tool
  • Start a Discussion
  • Write A Blog
  • Share A Build
  • Terms of Service
  • Privacy Policy
Explore with AI
  • ChatGPT
  • Gemini
  • Claude
  • Grok
  • Perplexity
Agent Experience
  • llms.txt
Theme
With AI, Everyone is a Dev. EveryDev.ai © 2026
    1. Home
    2. Tools
    3. Darkmoon
    Darkmoon icon

    Darkmoon

    Autonomous Systems

    Autonomous AI penetration testing platform with 18 specialized agents and 80+ integrated tools that runs full offensive security campaigns and delivers validated, evidence-backed findings.

    Visit Website

    At a Glance

    Pricing
    Open Source
    Free tier available

    Open source self-hosted engine, free forever under GPLv3.

    Pro: €119/mo
    Custom: Custom/contact

    Engagement

    Available On

    macOS
    Linux
    Web
    API
    CLI

    Resources

    WebsiteDocsGitHubllms.txt

    Topics

    Autonomous SystemsApplication SecurityMulti-agent Systems

    Alternatives

    HexStrike AIPentestAgentVibe Proxy
    Developer
    ASC-ITToulouse, FranceEst. 2018

    Listed Jun 2026

    About Darkmoon

    Darkmoon is an autonomous AI-powered penetration testing platform built by ASC-IT in Toulouse, France. It orchestrates 18 specialized AI agents and over 80 integrated security tools to conduct end-to-end offensive security campaigns without manual intervention. The core engine is open source under GPLv3, with a commercial Pro licence adding a hardened sealed runtime, managed live command center, and branded reporting.

    What It Is

    Darkmoon sits in the autonomous offensive security category — it is not a passive vulnerability scanner but a multi-agent system that reasons about a target, fingerprints the technology stack, models the attack surface, dispatches domain-specific sub-agents, validates findings with real payloads, and generates structured audit reports. The platform is built around a strict security-by-design principle: the AI never directly executes tools. All tool calls flow through an MCP (Model Context Protocol) gateway that acts as a controlled execution layer, keeping the AI reasoning layer isolated from the actual toolbox.

    Architecture: AI Brain, MCP Gatekeeper, Docker Toolbox

    The execution pipeline follows a clear separation of concerns:

    • OpenCode (AI Brain) — reasons, plans, and delegates tasks to sub-agents
    • MCP Darkmoon (Security Gatekeeper) — validates and routes every tool call
    • Docker Toolbox — runs isolated security tools inside containers

    The master orchestrator agent detects up to 14 technology signals from the target and routes the campaign to the appropriate specialists, either sequentially or in parallel, with cascade depth capped at three levels to prevent runaway recursion. A live SSE (Server-Sent Events) dashboard streams every finding, infrastructure node, and agent event in real time.

    Agent Coverage and Toolbox

    Darkmoon ships 18 specialized agents covering:

    • Web & API exploitation — SQLi, XSS, SSRF, IDOR, RCE, SSTI, deserialization, JWT abuse, file upload, and path traversal, validated with real payloads
    • Kubernetes attack chains — RBAC escalation, DIND exploitation, node escape, etcd SSRF, privileged container breakout, crypto-miner detection, and CIS benchmarking
    • Active Directory takeover — AS-REP roasting, Kerberoasting, BloodHound, NTLM relay, LSASS dump, DCSync, and ADCS ESC1–ESC8, Golden & Silver tickets
    • CMS-specific agents — WordPress, Drupal, Joomla, Magento, PrestaShop, Moodle
    • Stack-specific agents — PHP/Laravel, Node/Express, NestJS/Next.js, Flask/Django, ASP.NET/Blazor, Spring Boot, Ruby on Rails

    The integrated toolbox includes subfinder, httpx, naabu, katana, nuclei, ffuf, wpscan, sqlmap, hydra, hashcat, netexec, BloodHound, Impacket, mimikatz, kubectl, kubescape, and more — all coordinated through the MCP gateway.

    Runtime Security Model

    The Pro licence adds a hardened sealed runtime with several tamper-resistance mechanisms:

    • AES-256-GCM sealed storage with keys derived from the licence and hardware fingerprint, resealed every 30 seconds
    • Hardware-bound licensing derived from MAC address and CPU model
    • SHA-256 binary integrity watchdog re-verifying critical binaries every 2 seconds, triggering immediate zeroize on tampering
    • Continuous debugger and tracer detection (gdb, strace, ltrace, frida, lldb)
    • Read-only rootfs with tmpfs writable paths, seccomp, and no-new-privileges
    • Secret redaction scrubbing model API keys and licence keys from all log output

    Update: Darkmoon v1.1.0

    The GitHub repository shows the latest release as v1.1.0 — "Authoritative reporting & adversarial qualification", published on 15 June 2026. The repository was last pushed on 19 June 2026, indicating active development. The project is written primarily in Python and has accumulated 408 stars and 71 forks on GitHub as of the data snapshot. Three deployment paths are offered: self-hosted licence via Docker, a managed Pentest on Demand service where ASC-IT experts run the engagement, and a Partner/MSSP reseller program with Stripe-powered billing.

    Darkmoon - 1

    Community Discussions

    Be the first to start a conversation about Darkmoon

    Share your experience with Darkmoon, ask questions, or help others learn from your insights.

    Pricing

    FREE

    Community

    Open source self-hosted engine, free forever under GPLv3.

    • Full autonomous engine on GitHub
    • GPLv3 — audit & modify freely
    • 18 AI agents + 80 integrated tools
    • MCP-gatekept tool execution
    • Community support

    Pro

    For professional pentesters and teams. Hardened sealed runtime and managed live command center.

    €119/mo
    billed annually
    €149/mo monthly
    • Everything in Community
    • Hardened, sealed runtime
    • Managed live command center
    • All report formats & branded PDF
    • Hardware-bound licence
    • Priority email support

    Custom

    For enterprises, MSSPs and resellers. Tailored to scope.

    Custom
    contact sales
    • Everything in Pro
    • Multi-seat shared workspace
    • Custom report branding
    • Partner / reseller program
    • Dedicated onboarding & SLA
    View official pricing

    Capabilities

    Key Features

    • 18 specialized AI agents
    • 80+ integrated security tools
    • Multi-agent orchestration with cascade depth control
    • Live SSE dashboard with real-time event streaming
    • MCP-gatekept tool execution (AI never gets shell access)
    • Web & API exploitation (SQLi, XSS, SSRF, IDOR, RCE, SSTI)
    • Kubernetes attack chain coverage
    • Active Directory takeover (Kerberoasting, BloodHound, DCSync, ADCS ESC1-ESC8)
    • CMS-specific agents (WordPress, Drupal, Joomla, Magento, PrestaShop, Moodle)
    • Infrastructure graph mapping
    • ISO 27001, HackerOne, and Bugcrowd report formats
    • Branded password-protected PDF reports with CVSS 3.1 and MITRE ATT&CK mapping
    • AES-256-GCM sealed storage
    • Hardware-bound licensing
    • Binary integrity watchdog
    • Debugger and tracer detection
    • Read-only rootfs with seccomp sandbox
    • Secret redaction in logs
    • Docker-based self-hosted deployment
    • CI/CD integration support
    • Bug bounty mode with FOCUS/EXCLUDE flags
    • GPLv3 open-source core engine

    Integrations

    Docker
    Docker Compose
    OpenRouter
    Anthropic Claude
    OpenAI
    Ollama
    llama.cpp
    Nuclei
    subfinder
    httpx
    naabu
    katana
    ffuf
    wpscan
    sqlmap
    hydra
    hashcat
    netexec
    BloodHound
    Impacket
    mimikatz
    kubectl
    kubescape
    wafw00f
    arjun
    Playwright
    Masscan
    dirb
    WhatWeb
    CMSeeK
    Waybackurls
    Lightpanda
    Stripe
    API Available
    View Docs

    Demo Video

    Darkmoon Demo Video
    Watch on YouTube

    Ratings & Reviews

    No ratings yet

    Be the first to rate Darkmoon and help others make informed decisions.

    Developer

    ASC-IT

    ASC-IT builds Darkmoon, an autonomous AI penetration testing platform, from Toulouse, France. The team develops open-source offensive security tooling under GPLv3 and offers managed pentest services alongside the self-hosted platform. ASC-IT also runs a partner and MSSP reseller program with Stripe-powered billing built in.

    Founded 2018
    Toulouse, France
    7 employees

    Used by

    Various regional French businesses and…
    Read more about ASC-IT
    WebsiteGitHub
    1 tool in directory

    Similar Tools

    HexStrike AI icon

    HexStrike AI

    An open-source MCP server that lets AI agents autonomously run 150+ cybersecurity tools for automated penetration testing, vulnerability discovery, and bug bounty automation.

    PentestAgent icon

    PentestAgent

    An open-source AI agent framework for black-box penetration testing, supporting autonomous multi-agent workflows, MCP integration, and built-in security tools.

    Vibe Proxy icon

    Vibe Proxy

    An AI-powered web security testing tool that combines proxy traffic interception with AI agents to accelerate penetration testing workflows.

    Browse all tools

    Related Topics

    Autonomous Systems

    AI agents that can perform complex tasks with minimal human guidance.

    300 tools

    Application Security

    AI tools for securing software applications and identifying vulnerabilities.

    90 tools

    Multi-agent Systems

    Platforms for creating and managing teams of AI agents that can collaborate.

    216 tools
    Browse all topics
    Back to all toolsSuggest an edit
    ratings
    discussions