Dark Moon

Dark Moon

Autonomous AI penetration testing platform with self-hosted agents

73/100Safe BetFree planFreemium

Pick Darkmoon if you want autonomous, evidence-backed pentesting without sending sensitive data to third-party clouds — the free Community edition is a rare open-source entry point. But the hard self-hosting and Linux requirements will filter out less technical buyers. If you value control and auditability over convenience, it's worth the setup.

Verified 4d ago · liveness 73/100 · cite: rightaichoice.com/tools/dark-moon

Best for
  • Professional pentesters running deep, multi-layer offensive assessments
  • Red teams needing autonomous continuous campaigns with evidence-backed findings
  • SOCs automating penetration testing with full control over infrastructure
  • Bug bounty hunters targeting complex web, AD, cloud, and IoT environments
Not ideal for
  • Beginners without Linux or self-hosting experience
  • Organizations that require a cloud-based SaaS with zero setup
  • Teams expecting a simple vulnerability scanner without exploit chaining
Visit Website

AdvancedFor Community: expect 1-2 hours to install and configure if you're comfortable with Docker/Linux. For Pro: similar setup, plus license activation with hardware fingerprint. Custom may take days.Web · CLIAPI availableVerified 4d ago
Pricing
Free plan
FreemiumFree tier3 plans4 hidden costs
Learning curve
Advanced
For Community: expect 1-2 hours to install and configure if you're comfortable with Docker/Linux. For Pro: similar setup, plus license activation with hardware fingerprint. Custom may take days.
Runs on
WebCLI
API available · 15 integrations
Who it's for
Professional pentesterRed team operatorDevSecOps engineer
Live sentiment
Is Dark Moon actually worth it?

We scan live Reddit threads, YouTube comments, X posts, G2 reviews and other communities — and hand you an honest verdict in under a minute.

  • Honest verdict, not marketing
  • Real pros & cons from real users
  • Attributed quotes with receipts
Run a free scan

3 free scans · no card needed

Skip it if

Skip Darkmoon if you need a managed cloud SaaS with zero setup, lack Linux proficiency, or expect a simple point-and-click scanner without infrastructure management.

The 30-second take
Biggest gripe

Pro edition requires annual billing at €149/month (€1788/year) — you can't pay monthly.

Price reality

Darkmoon's Community edition is free (GPLv3) — rare for an autonomous pentesting platform. Pro at €149/month (annual) is competitive with enterprise scanners (e.g., Pentest-Tools.com, HackerOne) but requires self-hosting. For teams that can manage infrastructure, it's cost-effective; for those wanting SaaS, look elsewhere.

In short

Dark Moon — Autonomous AI penetration testing platform with self-hosted agents. Best for Professional pentesters running deep, multi-layer offensive assessments, Red teams needing autonomous continuous campaigns with evidence-backed findings, SOCs automating penetration testing with full control over infrastructure. Free to start; paid plans from €1491788/mo.

What people actually say about Dark Moon — is it worth it?

We ran a structured research pass across product reviews, community discussions, and post-purchase forum threads to surface the patterns vendors won't publish themselves. Below: the recurring strengths, the hidden costs people mention most, and the cohort that consistently regrets adopting this tool.

61 mentions across 4 sources (YouTube, App Store, GitHub, Lemmy) · researched Aug 21, 2026.

29% positive71% critical
Recurring strengths
  • +Autonomous orchestration with 33 specialized agents (Pro) covers full offensive security lifecycle.
  • +Privacy Gateway tokenizes sensitive data before LLM, adding strong privacy protection.
  • +Self-hosted, open-source with 80+ integrated tools for comprehensive testing.
  • +Cascade control with dynamic routing and 3-level depth cap gives targeted exploitation.
  • +Real-time SSE dashboard streams findings, infrastructure nodes, and agent events live.
Recurring frustrations
  • Repeated GitHub complaints about installation failures, especially on ARM64.
  • CLI mode often returns nothing without error, logs, or progress feedback.
  • Missing authentication header and custom API provider configuration issues frustrate users.
  • Limited documentation for troubleshooting common setup problems.
  • Hardware-bound licensing can break in containerized or dynamic environments.
Patterns worth knowing
Installation and setup are the biggest pain point — numerous GitHub issues on missing assets, ARM64 incompatibility, and silent CLI failures.
Seen on GitHub
Privacy Gateway and autonomous agent orchestration are the standout features that attract security professionals.
Seen on GitHub
Lack of reliable support and slow issue resolution discourages enterprise adoption.
Seen on GitHub
Learning curve
advancedProductive in ~A few hours to a day of setup and configuration
Hidden costs people mention
  • LLM API usage fees (e.g., Anthropic API) required to run the core engine, which can add up on large campaigns.
  • Hardware requirements for self-hosting (CPU, RAM, storage) and possible AWS/GCP costs if run in cloud.

Viability Score

73/100
Safe Bet

How well maintained and how widely used is Dark Moon? Built from what the vendor actually publishes (docs, changelog, tutorials, integrations, pricing), whether the site is live, and how much real users discuss it. How we calculate this

Recent activity
90
Traction
100
Site health
95
User sentiment
29
What the vendor publishes
40

Last calculated: September 2026

How we score →

Key Features

  • Autonomous orchestration with specialized AI agents (18 Community, 33 Pro)
  • 80+ integrated tools coordinated by AI
  • Cascade control with dynamic routing and 3-level depth cap
  • Real-time SSE dashboard streaming findings and events
  • Full-stack web exploitation: SQLi, XSS, SSRF, RCE, SSTI, IDOR
  • Active Directory takeover: Kerberoasting, DCSync, ADCS, Golden tickets
  • Cloud identity pivots: AWS/Azure/GCP metadata, Key Vault extraction
  • IoT firmware analysis with Binwalk/squashfs extraction
  • Privacy Gateway tokenization of sensitive data before LLM
  • AES-256 sealed storage with 30-second reseal
  • Hardware-bound licensing with machine code fingerprint
  • Anti-tamper detection for gdb, strace, frida, lldb
  • Read-only rootfs + seccomp sandbox, unprivileged process
  • Secret redaction in logs (stdout/stderr)
  • Publication-ready reports: ISO 27001, HackerOne, Bugcrowd formats

About Dark Moon

FreemiumAdvancedAPI availableWeb · CLI

Darkmoon is an open-source, self-hosted penetration testing platform that orchestrates a team of specialized AI agents to run full offensive security campaigns — from reconnaissance and exploitation to reporting. It models the attack surface of web apps, cloud infrastructure, Active Directory, Kubernetes, and IoT devices, then dispatches the right agents with cascade control to chain real exploits and deliver validated, evidence-backed findings. The live SSE dashboard streams every finding, infrastructure node, and agent event in real time, while the platform exports publication-ready reports in ISO 27001, HackerOne, and Bugcrowd formats with CVSS 3.1 scoring and MITRE ATT&CK mapping. The core engine detects 14 technology signals from the target and routes campaigns to specialist agents covering full-stack web exploitation, Active Directory takeover, cloud identity pivots, and IoT firmware analysis. A Privacy Gateway tokenizes every sensitive value — IPs, hostnames, emails, credentials — before it reaches the LLM, so the model reasons only on deterministic placeholders while real values are re-injected locally. Exfiltration attempts are blocked, and all outputs are sanitized before returning to the model. Darkmoon runs in a hardened runtime: AES-256 sealed storage (resealed every 30 seconds), hardware-bound licensing, a binary integrity watchdog, anti-tamper detection, a read-only rootfs with seccomp sandbox, and secret redaction in logs. Recent real-world campaigns documented by the team show Darkmoon chaining complex attack paths: an Entra ID tenant takeover via a deleted blob and ROPC without MFA, an Azure helpdesk-to-Global Admin chain across four identities, and SSRF via gopher to GCP metadata to steal a service account token. Static firmware analysis found a backdoor and credentials in an IoTGoat image without ever touching the device, and a GitLab CE audit uncovered 13 findings. Darkmoon comes in three editions: the free Community edition (18 agents,

Behind the Verdict

We'd reach for Darkmoon when you need deep, autonomous security testing and can't afford to share sensitive data with third-party LLM clouds. The tool's core strength is its orchestration: the master agent detects 14 technology signals and dispatches specialists — 18 in Community, 33 in Pro — with cascade control that prevents runaway recursion. You're not just running a scanner; you're running a campaign that chains real exploits and delivers validated findings, which is rare in open-source tools. But there's a catch: Darkmoon demands Linux proficiency and self-hosting, with Docker and hardware-bound licensing. There's no cloud SaaS option, so if you're not comfortable managing infrastructure, this isn't for you. The free Community edition is a great entry point, but it's capped at 18 agents and lacks the hardened runtime and export formats — those come only with the Pro tier at €149/month (billed annually), which is a significant jump for individual pentesters. Compared to alternatives like Metasploit or Burp Suite, Darkmoon offers AI-driven autonomy and privacy that those tools lack, but it's also younger and less battle-tested in the community. The documented real-world campaigns — Entra ID tenant takeover, Azure helpdesk-to-Global Admin, GCP SSRF — show serious capability, but also highlight that it's not for beginners: you need to understand AD, cloud, and IoT internals to get value. In practice, the Privacy Gateway is a standout: it tokenizes every sensitive value before it hits the LLM, blocks exfiltration, and keeps your data local — a major selling point for security-conscious organizations. The runtime hardening is serious too, with AES-256 sealed storage, integrity watchdogs, and anti-tamper detection. Where it bites: the setup is non-trivial, and the

Researching Dark Moon? Get your full AI stack in 60 seconds.

Free, no signup — tell us your goal and get tools matched to your budget & existing stack.

Real-world workflow fit

Concrete scenarios for the personas Dark Moon actually fits — and what changes day-one when you adopt it.

Professional pentester

Run a full web app assessment

Outcome: Authenticate to target, scope in, launch Darkmoon. Agents enumerate subdomains, crawl, and exploit SQLi/SSRF, chaining to RCE. Report generated in HackerOne format.

Red team operator

Continuous AD attack path mapping

Outcome: Darkmoon uses BloodHound to map attack paths, performs Kerberoasting and DCSync, and reports validated findings via SSE dashboard and PDF report.

DevSecOps engineer

Integrate into CI/CD for automated security testing

Outcome: Trigger Darkmoon on new builds via CLI, receive findings and reports automatically, and enforce security gates with evidence-backed results.

Use Cases

  • Automate continuous penetration testing of web applications and APIs
  • Map and exploit Active Directory attack paths using BloodHound and impacket
  • Assess Kubernetes cluster security with kubectl and kubescape
  • Generate ISO 27001 and HackerOne-compliant reports from automated campaigns
  • Monitor live attack progress and infrastructure graphs from the command center
  • Validate security controls effectively: as shown in the OpenNHP test, Darkmoon found 51 issues on exposed surface but zero on NHP-protected hosts, proving its ability to respect protected perimeters

Models Under the Hood

Claude

as of 2026-09-02

Limitations

  • Darkmoon is self-hosted for both Community and Pro editions; no cloud SaaS option is mentioned.
  • Pro's hardware-bound licensing may complicate multi-instance or ephemeral deployments.
  • Cascade depth is capped at three levels to prevent runaway recursion, potentially limiting deep attack chains.
  • The tool requires Linux proficiency and self-hosting setup.

as of 2026-08-21

Verification history

We have re-verified Dark Moon 7 times since . Each pass re-reads the vendor's own pages and re-checks every listed field against that evidence; passes where nothing had changed are marked as such.

  1. re-verified summary, description, our verdict, our analysis, pricing model, pricing tiers, features, integrations, who it suits, who should skip it
  2. re-verified summary, description, our verdict, our analysis, pricing model, pricing tiers, features, integrations, who it suits, who should skip it
  3. re-verified summary, description, our verdict, our analysis, pricing model, pricing tiers, features, integrations, who it suits, who should skip it
  4. re-verified summary, description, our verdict, our analysis, pricing model, pricing tiers, features, integrations, who it suits, who should skip it
  5. re-verified summary, description, our verdict, our analysis, pricing model, pricing tiers, features, integrations, who it suits, who should skip it
  6. re-verified summary, description, our verdict, our analysis, pricing model, pricing tiers, features, integrations, who it suits, who should skip it

Showing the 6 most recent of 7 verification passes.

Free to cite with attribution — this page re-verifies continuously.

12-month cost

Project the real annual outlay, including the implied monthly cost when only an annual tier is published.

Annual total
Free
Over 12 months
Effective monthly
Free
Billed monthly

Vendor list price only. Add-on usage, seat overages, and contract minimums are surfaced under Hidden costs & gotchas.

Plans compared

For each published Dark Moon tier: who it actually fits, and what it adds vs. the previous tier. Cross-reference the cost calculator above for projected annual outlay.

Community

$0/mo

Ideal for

Solo pentesters or small teams who want a free, open-source autonomous pentesting tool and can self-host on their own Linux infrastructure.

What this tier adds

Starting tier: free forever, GPLv3, includes 18 AI agents and 80+ tools, but lacks advanced cloud/AD/IoT modules and hardware-bound licensing.

Pro

€149/mo (billed annually at €1788)

Ideal for

Professional pentesters and teams that need 33 agents, full-stack exploitation (AD, cloud, IoT), and hardened runtime with priority support.

What this tier adds

Adds 15 more agents, hardware-bound licensing, full report formats (ISO 27001, HackerOne, Bugcrowd with branded PDF), and priority email support.

Custom

Contact sales

Ideal for

Enterprises, MSSPs, and resellers that need multi-seat collaboration, custom branding, dedicated onboarding, and SLA support.

What this tier adds

Adds multi-seat shared workspace, custom report branding, partner/reseller program, and SLA — pricing tailored to scope.

Hidden costs & gotchas

What the public pricing page doesn't put in bold. Captured from pricing-page footnotes, contract terms, and recurring complaints.

  • Pro edition requires annual billing at €149/month (€1788/year) — you can't pay monthly.
  • Hardware-bound licensing means moving to a new machine or ephemeral environments may require re-licensing or additional coordination.
  • Self-hosting requires your own infrastructure (servers, storage, patch management) — no included cloud.
  • Custom edition (multi-seat, SLA, branded reports) requires contact sales; pricing not public.

Where the pricing makes sense

The company stage and team size where Dark Moon's pricing actually pencils out — and where peers do it cheaper.

Darkmoon's Community edition is free (GPLv3) — rare for an autonomous pentesting platform. Pro at €149/month (annual) is competitive with enterprise scanners (e.g., Pentest-Tools.com, HackerOne) but requires self-hosting. For teams that can manage infrastructure, it's cost-effective; for those wanting SaaS, look elsewhere.

Setup time & first value

How long it actually takes to get something useful out of Dark Moon — broken out by persona, not the marketing-page minute.

For Community: expect 1-2 hours to install and configure if you're comfortable with Docker/Linux. For Pro: similar setup, plus license activation with hardware fingerprint. Custom may take days.

Switching to or from Dark Moon

How to bring data in from common predecessors and how to get it back out — written for the switcher, not the buyer.

Migrating in
  • From Nessus/OpenVAS: import scan results and use Darkmoon for deeper exploitation — export reports in standard formats.
Migrating out
  • To Pentest-Tools.com: if you need SaaS, export findings and reports as JSON/PDF and import into the platform.

Integrations

subfinderhttpxnaabukatananucleiffufwpscansqlmaphydrahashcatnetexecbloodhoundimpacketmimikatzkubectl

Resources & Guides

Tutorials & Learning

Official links

Tools that pair well with Dark Moon

Common stack mates teams adopt alongside Dark Moon, with the specific reason each pairing earns its keep.

Featured Head-to-Head Comparisons

Alternatives to Dark Moon

View all
Mindgard

Mindgard

Automated AI red teaming platform that continuously discovers, assesses, and defends AI systems and agents.

Contact SalesTry
Anthropic Cybersecurity Skills

Anthropic Cybersecurity Skills

Open-source library of 817 structured cybersecurity skills for AI agents, MITRE-mapped and free.

FreeTry
Veria Labs

Veria Labs

Autonomous AI pentester that maps attack surfaces, proves exploits, and drafts fixes.

Contact SalesTry

Frequently Asked Questions

Used Dark Moon? Help shape our editorial sentiment research.