ASCIT31/Dark-Moon
Autonomous AI pentesting engine, continuous offensive security across web, cloud, identity, CI/CD, IaC, databases, Active Directory, Kubernetes and IoT firmware. Agentic reasoning plus real exploit execution deliver proof-based vulnerabilities. Privacy gateway: the LLM never sees your real IPs, hosts or creds, nothing leaves your perimeter.
What it solves
DarkMoon is an autonomous AI penetration testing platform designed to automate the repetitive, toil-heavy parts of security assessments. It allows security teams to run full-scale, black-box penetration tests across diverse environments—including web apps, cloud infrastructure, Active Directory, and Kubernetes—without manually executing every tool and command.
How it works
DarkMoon uses an orchestrator (OpenCode) that reasons and plans attack strategies. It dispatches 50 specialized AI agents (e.g., CMS-specific, Cloud-provider, or Database agents) that execute real offensive tools (like Nuclei, sqlmap, and BloodHound) via a controlled Model Context Protocol (MCP) layer. To ensure privacy, it uses a local tokenization gateway that replaces sensitive data like IPs and credentials with placeholders before they reach the LLM, rehydrating them only when executing tools locally.
Who it’s for
It is built for security teams, DevSecOps engineers, red teamers, and ethical hacking professionals who want to automate vulnerability discovery and evidence collection.
Highlights
- Privacy-First Architecture: Local tokenization ensures sensitive target data never reaches the LLM.
- Broad Scope: Supports web, APIs, Active Directory, Kubernetes, and major cloud providers (AWS, Azure, GCP).
- Evidence-Based: Every finding includes the exact command and raw output for easy reproduction.
- Tool-Rich: Integrated Docker toolbox with over 50 professional security tools.
- Local LLM Support: Can run entirely on local models via Ollama or llama.cpp to keep data within the infrastructure.
相關
- 專案
- 專案
- 專案
- 專案
- 專案