Darkmoon
<p> Autonomous penetration testing platform </p> <p> <a href="https://www.producthunt.com/products/darkmoon?utm_campaign=producthunt-atom-posts-feed&utm_medium=rss-feed&utm_source=producthunt-atom-posts-feed">Discussion</a> | <a href="https://www.producthunt.com/r/p/1175199?app_id=339">Link</a> </p>
Last verified:
What is Darkmoon?
Darkmoon is an autonomous AI penetration testing platform that orchestrates offensive security campaigns end to end. It uses a master agent to detect technology signals, route work to specialist agents, and coordinate tools across recon, web applications, Kubernetes, Active Directory, and more.
The platform emphasizes real pentest behavior rather than one-pass scanning. It validates findings with real payloads, maps infrastructure and attack paths, streams events live to a dashboard, and generates structured reports for security teams.
Darkmoon is built for professional pentesters, red teams, MSSPs, and enterprises that want autonomous offensive testing with evidence-backed outputs. It is also aimed at teams that want to self-host the platform, keep control of their tooling, and integrate the results into formal reporting workflows.
The website frames Darkmoon as both a product and a framework for running campaigns locally or via managed service. Its design focuses on automation, reproducibility, auditability, and hardened execution rather than a simple vulnerability scanner.
Darkmoon pricing
Pricing model: Freemium
Community is free forever under GPLv3 and includes the full autonomous engine on GitHub, 18 AI agents, 80 integrated tools, MCP-gatekept tool execution, and community support. Pro costs €149 per month billed as €1788 annually and adds the hardened sealed runtime, managed live command center, all report formats with branded PDF, a hardware-bound license, and priority email support. Custom pricing is available for enterprises, MSSPs, and resellers, with multi-seat shared workspaces, custom branding, partner/reseller options, dedicated onboarding, and SLA. The site also offers Pentest on Demand as a managed service with a flat rate and a debriefed secure report.
Darkmoon pros
- 80+ integrated tools coordinated by AI
- 18 specialized AI agents
- Multi-agent dispatch based on 14 technology signals
- Sequential or parallel campaign execution
- Cascade depth capped at three levels
- Live SSE stream for findings and events
- Infrastructure graph with nodes and connections
- Validates findings with real payloads
- Supports web and API exploitation
- Supports Kubernetes attack-chain assessment
- Supports Active Directory takeover paths
- Publication-ready reports in Markdown and PDF
- CVSS 3.1 scoring included
- MITRE ATT&CK mapping included
- Hardened runtime with AES-256-GCM sealed storage
- Hardware-bound licensing
- Binary integrity watchdog
- Debugger and tracer detection anti-tamper
- Read-only root filesystem with seccomp
- Secret redaction in logs
- Self-hosted free community edition
- Managed pentest service available
- Partner/reseller program available
- Evidence-backed reporting for same-day action
Darkmoon cons
- Large and specialized offensive-security focus
- Primarily aimed at experienced security teams
- Requires self-hosting for the free edition
- Hardware-bound licensing may limit portability
- Managed features are tied to paid plans
- Free plan has only community support
- Advanced reporting is gated behind Pro
- Enterprise features require custom pricing
- Potentially complex for smaller teams
- Not positioned as a general-purpose scanner
Frequently asked questions about Darkmoon
What does Darkmoon actually do?
Darkmoon runs autonomous offensive security campaigns from planning through reporting. It identifies technology signals, routes tasks to specialist agents, executes tools, validates findings with payloads, builds an infrastructure graph, and produces structured output that a security team can use.
Is Darkmoon just a scanner?
No. The site explicitly contrasts it with a scanner and says it behaves like an autonomous security conductor. It does more than one-pass signature checks by chaining recon, exploitation, validation, mapping, and reporting into a full campaign.
What kinds of targets does Darkmoon support?
Darkmoon presents support for web and API testing, Kubernetes attack chains, and Active Directory takeover paths. The site also lists technologies such as WordPress, GraphQL, headless browsers, Node, Django, ASP.NET, Laravel, Magento, and other common stacks.
How does the AI orchestration work?
A master agent detects 14 technology signals and dispatches work to the right specialists. The site says campaigns can run sequentially or in parallel, and the cascade depth is capped at three levels to prevent runaway recursion.
What reporting formats are available?
The platform generates publication-ready reports in Markdown and branded password-protected PDF. The site also says those reports include CVSS 3.1 scoring and MITRE ATT&CK mapping, and it references ISO 27001, HackerOne, and Bugcrowd formats.
What is included in the free plan?
The Community plan is free forever and is the self-hosted GPLv3 edition. It includes the full autonomous engine on GitHub, 18 AI agents, 80 integrated tools, MCP-gatekept tool execution, and community support.
What does the Pro plan add?
Pro adds the hardened sealed runtime, a managed live command center, all report formats with branded PDF, a hardware-bound license, and priority email support. The site lists it at €149 and says it is billed annually at €1788.
Does Darkmoon offer a managed service?
Yes. The site offers Pentest on Demand, where you describe the target, sign the framework online, pay a flat rate, and Darkmoon’s experts run the engagement. The result is a debriefed report delivered to a secure client space.
Can Darkmoon be self-hosted?
Yes. The website says the Community edition is free forever and self-hosted, and it also describes Pro as a self-hosted option with a hardware-bound license and Docker install.
Who is Darkmoon for?
Darkmoon is aimed at professional pentesters, red teams, security teams, MSSPs, enterprises, and resellers. The website positions it for users who want autonomous offensive testing, validated evidence, and formal reports rather than simple vulnerability scans.