Skip to content

Entry

Darkmoon

Appears in 10 awesome lists

🟢⚠️ — Autonomous AI penetration-testing platform that orchestrates specialized web, AD, Kubernetes, CMS, and framework agents through an MCP-controlled Docker toolbox with local privacy-tokenization for sensitive target data. — note: GPL-3.0 licensed; heavy Docker/LLM stack, use only for…;…

Open github.comascit31/dark-moon

Found in these lists

Awesome AI Security Tools

Section: Pentest & Red-Team Agents · 🟢⚠️ — Autonomous AI penetration-testing platform that orchestrates specialized web, AD, Kubernetes, CMS, and framework agents through an MCP-controlled Docker toolbox with local privacy-tokenization for sensitive target data. — note: GPL-3.0 licensed; heavy Docker/LLM stack, use only for…;…

FreshScore 85

Awesome Bug Bounty Tools

Section: AI Agents · Open source (GPL-3.0) autonomous AI penetration testing platform that orchestrates 80+ tools over MCP with dedicated per-technology offensive sub-agents (GraphQL, Spring Boot, ASP.NET, Node.js, Flask, PHP, Ruby) and a per-finding evidence trail.

FreshScore 89

Awesome Cloud Native

Section: Security & Compliance · Open source autonomous AI penetration testing platform that orchestrates 80+ offensive tools via Markdown playbooks, with a proof trail per finding.

FreshScore 87

Awesome Gemini CLI

Section: New · GPL-3.0 autonomous penetration testing platform: per-technology agents, 80+ tools, proof-based findings, and a privacy gateway that keeps target data from the model.

FreshScore 82

Awesome Infosec

Section: Massive Online Open Courses · Open source autonomous penetration testing platform (GPLv3). 50 specialist agents over MCP with proof of exploitation on every finding, runs locally.

FreshScore 82

Awesome Open Source AI

Section: 4. Agentic AI & Multi-Agent Systems · Open-source autonomous AI pentest platform and MCP host orchestrating 80+ offensive tools via per-tech offensive sub-agents, with Active Directory and Kubernetes support. GPL-3.0 licensed.

FreshScore 89

SOCIAL MEDIA

Section: Recon · Open source (GPL-3.0) autonomous AI penetration testing platform covering web, API, Active Directory and Kubernetes, orchestrating 80+ offensive tools as an MCP host with proof of exploitation and a local privacy gateway (the LLM never sees real IPs or credentials).

FreshScore 86

Awesome Proxmox VE

Section: Security Tools & Best Practices · Open source (GPL-3.0) autonomous AI penetration testing platform covering web, API, Active Directory and Kubernetes.

FreshScore 82

Awesome Web Security

Section: Penetration Testing · Open source autonomous AI penetration testing platform that orchestrates 80+ offensive tools via Markdown playbooks and MCP across web, cloud, Active Directory and Kubernetes, with an evidence trail per finding by @ASCIT31.

FreshScore 87

Awesome DevOps

Section: Security · Open source autonomous AI penetration testing platform that orchestrates 80+ offensive tools via Markdown playbooks with a proof trail per finding.

FreshScore 87

Trivy

A Simple and Comprehensive Vulnerability Scanner for Containers and other Artifacts, Suitable for CI. Trivy detects vulnerabilities of OS packages (Alpine, RHEL, CentOS, etc.) and application dependencies (Bundler, Composer, npm, yarn, etc.). Checks containers and filesystems.

In 9 listsDetails

Keycloak

🆓 Open-source Identity and Access Management. Supports OIDC, OAuth 2 and SAML 2, LDAP and AD directories, password policies.

In 7 listsDetails

Checkov

Static analysis for infrastructure as code manifests (Terraform, Kubernetes, Cloudformation, Helm, Dockerfile, Kustomize) find security misconfiguration and fix them.

In 7 listsDetails

brood-box

🟢 — Experimental runner for coding agents in hardware-isolated microVMs with copy-on-write workspace snapshots, egress profiles, selective secret forwarding, and file-by-file review before applying changes. (Stacklok) — note: APIs and behavior are explicitly experimental; workspace-mode=direct…

In 6 listsDetails

syft

star:8295 A CLI tool and Go library for generating a Software Bill of Materials (SBOM) from container images and filesystems.

In 6 listsDetails

cosign

Container signing, verification, and transparency log for OCI artifacts.

In 6 listsDetails

Pomerium

Pomerium is a zero-trust context and identity aware access gateway inspired by BeyondCorp.

In 6 listsDetails

hashicorp/vault

A tool for securely accessing secrets. A secret is anything that you want to tightly control access to, such as API keys, passwords, certificates, and more.

In 7 listsDetails