ASC-IT is a French cybersecurity and software engineering company. We run offensive security assessments (web, Active Directory, cloud, Kubernetes, IoT) for companies that want continuous, evidence-based security, and we build Darkmoon: the open-source platform that runs a full penetration test on its own, and never lets the AI see your real data.
Point Darkmoon at a target you are authorized to test. 50 specialist AI agents reason, chain real exploits across web, APIs, Active Directory, Kubernetes, cloud (AWS, Azure, GCP), CI/CD, databases, IoT firmware and AI/LLM endpoints (OWASP LLM Top 10), and return proof for every finding: the exact command, the raw output, reproducible. Self-hosted, GPLv3, and thanks to the Privacy Gateway the model only ever sees IP_PRIVATE_001, never your real IPs, hosts or credentials.
|
|
|
|
|
|
| Repository | What it is |
|---|---|
| Dark-Moon | The platform. 50 agents, 50+ offensive tools orchestrated over MCP, Privacy Gateway, CI/CD native. git clone and run your first assessment in minutes. |
| darkmoon-scan-action | GitHub Action that runs the open-source engine in your pipeline. No license needed. Findings land as artifacts. |
| Darkmoon-Benchmarks | Open, reproducible benchmark of autonomous AI pentesters on public vulnerable labs. 57 real vulnerabilities on OWASP Juice Shop in 28.5 minutes, on a local LLM. |
| darkmoon-research | Evidence corpus: runs across cloud, identity, CI/CD, IaC, data and IoT firmware, validated on public labs. |
| Dark-Moon-CI-Demo | A demo pentest pipeline you can fork to see the Action in motion. |
| Awesome-AI-Penetration-Testing | Curated list of AI and LLM powered pentesting tools, platforms, benchmarks and research. |
Numbers refreshed daily from the GitHub API by a scheduled workflow.
|
|
Contributors Every agent's methodology is plain Markdown you can read, diff and fork. Contributions welcome: new agents, tools, benchmarks, translations. Start with the contributing guide and the good first issues. |
|
Penetration testing of web apps and APIs, Active Directory (Kerberos, privileged accounts, GPO and delegations), networks and IoT. Scoped, executed and reported with CVSS scoring and an encrypted video debrief. |
AWS, Azure and GCP security audits: IAM and identities, storage and data, network, logging, compliance. Kubernetes and container hardening, configuration review, remediation and continuous securing. |
Web and desktop applications, DevSecOps pipelines, AI agent platforms. Angular, NestJS, Next.js, Python, on Kubernetes. Fixed-price builds and long-term maintenance. |
TF1 Info · Help Net Security · Cyber Security News · DevOps.com · SecurityBrief UK · LinuxFr.org · LinuxSecurity · LinuxLinks · UnderNews · ScanNetSecurity (JP) · OpenNHP · Product Hunt
Listed in Help Net Security's hottest open-source security tools of the month (June 2026).
|
🧑💻 Contribute
Open an issue, send a PR, add an agent or a tool. Read each agent's methodology in |
🔐 Report a vulnerability Found something in Darkmoon or on our infrastructure? Please follow our security policy. No public issues for security reports. |
🤝 Work with us Pentest, cloud audit, DevSecOps or a product to build: asc-it.fr · Darkmoon Pro, Pentest on Demand and the partner programme: dark-moon.org. |




