
Dark-Moon agents-expansion-2026.08
Autonomous AI penetration testing platform with agentic reasoning, privacy gateway, and 50+ integrated tools for continuous offensive security across web, cloud, AD, and Kubernetes environments.
DarkMoon
Open-source autonomous AI penetration testing — finds, exploits and qualifies every vulnerability on your own infrastructure
⭐ Star DarkMoon · 🚀 Quick Start · 🧩 Integrations · 📊 Benchmark · 🔒 Darkmoon Pro · ▶️ Watch the demo (Pro)
DarkMoon is autonomous AI penetration testing for your own infrastructure. Point it at an authorized target and it runs the whole assessment on its own, then documents every finding with the exact command and raw output.
- 🟢 Truly open source. GPLv3 and self-hosted, every agent's methodology is plain Markdown you can read, diff and fork.
- 🎯 Finds AND proves. Each vulnerability ships with the exact command and raw output (exploitation is agent-asserted; the Pro remediation retest is the machine-verified step), so there is almost nothing to triage.
- 🔒 Runs on a local LLM + Privacy Gateway. The gateway tokenizes your real IPs, hosts and credentials locally, so the model reasons on placeholders while real values stay on your perimeter.
- 🧩 Everywhere you build. Run it from GitHub, GitLab, Jenkins, VS Code, JetBrains, n8n, Grafana or Splunk — the open-source edition works with the CLI-based ones. See the integrations ↓
See the open source engine (CLI)
The open source Darkmoon is a command line tool. This is what you get when you clone the repo. You launch an assessment from the command line and watch every agent, command and finding stream past in real time.
Kick off a run from the CLI. One |
Autonomous agents reason and exploit, live in your terminal. Here a sub-agent flags CVE-2019-9978 and pivots straight to exploitation. |
Recon and environment model. DarkMoon fingerprints the stack and confirms the attack surface before it strikes. |
Live MCP stream. Every command the agent runs and its raw output, timestamped, with |
Signal to agent dispatch. DarkMoon decides which specialist agents to deploy from exactly what it detects on the target.
As featured in Help Net Security · Cyber Security News · DevOps.com · SecurityBrief · LinuxLinks · IT Brief · ChannelLife
Quick Start
git clone https://github.com/ASCIT31/Dark-Moon.git
cd Dark-Moon
./install.sh
install.sh configures your LLM provider interactively (no need to edit docker-compose.yml) and builds the full stack:
./install.sh # skip form if .opencode.env already configured
./install.sh --init # force reconfiguration (cloud or local model)
./install.sh --help # show usage
Supports cloud providers (Anthropic, OpenAI, OpenRouter…) and local models (Ollama, llama.cpp). Then run your first assessment and watch it live:
./darkmoon.sh "TARGET: example.com"
./darkmoon.sh --log <session_id>
Prerequisites: Docker & Docker Compose, and an LLM API key (or a local model). GPU setup, environment variables and the full flags reference live in the Full Documentation.