Darkmoon
An open-source platform that runs automated penetration tests using a team of 18 AI agents coordinating 80+ security tools — probing your web apps, cloud, and infrastructure for real, exploitable vulnerabilities the way a human pentest team would, but con
🔗 Visit DarkmoonDescription
Traditional penetration testing means hiring a security firm once or twice a year to spend a week trying to break into your systems, which means any vulnerability introduced the day after they leave can sit undiscovered for months. Darkmoon's idea is to make that process continuous and automated: a coordinated team of AI agents does the reasoning and planning a human pentester would do, then uses real security tools to actually attempt exploits and confirm which vulnerabilities are genuinely exploitable — not just theoretical — across your web apps, cloud accounts, and internal network.
Darkmoon is an open-source (GPLv3), AI-powered autonomous penetration testing platform coordinating 18 specialized AI agents and 80+ integrated security tools to run end-to-end offensive security assessments across web applications, cloud, Active Directory, and Kubernetes, producing evidence-backed, publication-ready reports. Its architecture deliberately separates reasoning from execution: an orchestrator (OpenCode) talks to an LLM for planning, while a separate MCP-based control layer enforces an allow-list and runs every tool inside isolated Docker containers — the model never executes a shell directly, which limits the blast radius of an AI agent doing offensive security work. Pricing: Community tier is free and fully self-hosted with the complete engine; Pro is €149/month (or €1,788/year) adding a hardened runtime and managed command center; Enterprise is custom-priced for multi-seat workspaces; a one-off 'Pentest on Demand' managed engagement costs €799.
💬 Our review
The short version: Darkmoon is a serious, security-conscious answer to 'can AI actually do a real pentest,' and its free, self-hosted Community tier makes it worth trying for any security-minded team curious whether autonomous pentesting has matured enough to be useful yet.
The architectural choice to keep the LLM's reasoning strictly separated from actual tool execution — enforced through an MCP allow-list and Docker isolation rather than trusting the model to run commands directly — is exactly the kind of design decision a team should look for before letting an AI agent anywhere near offensive security tooling, and it's a meaningfully different (and safer) approach than 'give the model shell access and hope.' Traditional human-led pentest engagements typically cost many thousands of dollars for a single point-in-time assessment; Darkmoon's €799 one-off or €149/month continuous option is dramatically cheaper, though it should be treated as a complement to — not a full replacement for — a human-led assessment for compliance purposes (SOC2, PCI-DSS audits still generally expect a human-certified pentest). Being open source and self-hostable also means security teams can actually audit what the tool does rather than trusting a black box with credentials to their infrastructure.
💰 Pricing
📊 Global score
🤖 AI-enriched data
Community : gratuit, open source, auto-hébergé, moteur complet. Pro : €149/mois ou €1788/an (runtime durci, command center managé). Enterprise : sur devis. Pentest on Demand : €799/mission.
Pros
Séparation stricte raisonnement (LLM) / exécution (conteneurs isolés, allow-list MCP)
Version Community gratuite et open source, auditable et auto-hébergeable
Coût très inférieur à un pentest humain traditionnel (€799 vs plusieurs milliers d'euros)
Tests continus plutôt qu'un audit ponctuel annuel
Cons
Ne remplace pas un pentest humain certifié pour la conformité (SOC2, PCI-DSS)
Jeune plateforme, moins de retours d'usage qu'un pentest humain établi
Confier des identifiants d'infrastructure à un outil automatisé reste un choix à peser
