DEV Community

Mehdi BOUTAYEB profile picture

Mehdi BOUTAYEB

Cybersecurity architect, pentester and founder. Building Darkmoon, an open-source autonomous offensive security platform combining AI agents, real pentesting methodologies and infrastructure security.

Joined Joined on  github website
Your AI pentester is probably exfiltrating your client's data. Run it air-gapped instead.

Your AI pentester is probably exfiltrating your client's data. Run it air-gapped instead.

Comments
1 min read
6 open-source AI pentesters, one OWASP Juice Shop, ranked (reproducible)

6 open-source AI pentesters, one OWASP Juice Shop, ranked (reproducible)

Comments
1 min read
I let an autonomous AI agent try to escape its sandbox. Here is what still reached the internet.

I let an autonomous AI agent try to escape its sandbox. Here is what still reached the internet.

Comments
2 min read
I pointed an autonomous AI attacker at a zero-trust demo (OpenNHP). 51 findings on the exposed side, zero on the protected side.

I pointed an autonomous AI attacker at a zero-trust demo (OpenNHP). 51 findings on the exposed side, zero on the protected side.

Comments 1
2 min read
I ran an autonomous AI pentester on OWASP Juice Shop, on a LOCAL model. 57 real vulns in 28 min.

I ran an autonomous AI pentester on OWASP Juice Shop, on a LOCAL model. 57 real vulns in 28 min.

Comments
2 min read
Open source autonomous AI pentesting tools in 2026: an honest field guide

Open source autonomous AI pentesting tools in 2026: an honest field guide

Comments
3 min read
Let an AI pentest agent use a frontier model without leaking your network

Let an AI pentest agent use a frontier model without leaking your network

Comments
3 min read
How to read AI pentest benchmark claims: XBEN, 96 percent scores, and what they hide

How to read AI pentest benchmark claims: XBEN, 96 percent scores, and what they hide

Comments
1 min read
The real bottleneck in AI pentesting is validated exploitation, not discovery

The real bottleneck in AI pentesting is validated exploitation, not discovery

Comments
2 min read
Shannon and Darkmoon: two Claude powered pentesters, compared

Shannon and Darkmoon: two Claude powered pentesters, compared

Comments
1 min read
NodeZero is excellent, but it is SaaS: the self hosted open source path

NodeZero is excellent, but it is SaaS: the self hosted open source path

Comments
1 min read
Open source autonomous pentesting: Darkmoon compared to Strix, PentAGI and Shannon

Open source autonomous pentesting: Darkmoon compared to Strix, PentAGI and Shannon

Comments
1 min read
The open source AI pentest tools worth knowing in 2026

The open source AI pentest tools worth knowing in 2026

Comments
1 min read
Autonomous pentesting against Active Directory, without the black box

Autonomous pentesting against Active Directory, without the black box

Comments
1 min read
MCP for offensive security: orchestrating 80+ tools through an MCP host

MCP for offensive security: orchestrating 80+ tools through an MCP host

Comments
1 min read
Pentera alternatives in 2026, including the open source options

Pentera alternatives in 2026, including the open source options

Comments
1 min read
Why evidence matters more than model memory in AI pentesting

Why evidence matters more than model memory in AI pentesting

Comments
1 min read
We build Darkmoon: An Open-Source Autonomous Pentesting Platform

We build Darkmoon: An Open-Source Autonomous Pentesting Platform

Comments
5 min read
loading...