S.01Banks, fintech, payment and e-money institutions, insurers, investment firms

Penetration testing for financial entities, built for DORA and PCI.

Darkmoon attacks what a financial entity exposes: customer web and mobile APIs, open banking endpoints, payment integrations, identity and SSO, cloud tenants and the CI/CD pipelines that ship them. Every finding is qualified EXPLOITED, CONFIRMED or UNCONFIRMED with the evidence kept, which is what the general testing programme of DORA Chapter IV needs. It is not a threat-led penetration test (TLPT): that regime stays with your authority and external testers.

10 %
of NIS2 significant-impact incidents reported in 2025 affected banking (ENISA)
83.5 %
of finance-sector incidents in ENISA's 2024-25 period were hacktivist DDoS
€799
flat rate per managed engagement
50
specialist AI agents, 142 tools

S.03Financial services
Why financial entities are exposed

EU Member States reported that 10 % of NIS2 significant-impact incidents in 2025 affected banking, and hacktivist DDoS dominated finance-sector incidents (83.5 %) in ENISA's 2024-25 period. Behind the noise of denial of service sits the real risk: an API that lets one customer read another's account, a webhook that trusts a forged payment confirmation, a pipeline token that opens the production cloud account.

FindingsCVSS
SQL injection9.8
SSRF to metadata9.1
Broken access control8.7
JWT signature bypass7.5
Path traversal6.9

Every product is an API

Mobile banking, card controls, account aggregation, instant transfers, onboarding with document capture: all of it is a public API with authorization logic per customer, per account and per consent. Broken object-level authorization is the finding that turns a bug into a data breach.

$darkmoon run --scope identity
→AS-REP roast · 3 accounts
→Kerberoast · svc_sql cracked
→NTLM relay → DCSync
✓Domain Admin, proven

Payment integrations chain third parties

PSP callbacks, card tokenization services, SEPA batch exports, acquirer portals, fraud-scoring SaaS: each integration is a trust boundary with a secret, a signature and a timeout. A webhook accepted without signature verification is a forged payment.

Attack surfaceexposure

Identity is the perimeter

Customer IAM, strong customer authentication flows, back-office SSO on Entra ID, privileged access of operations teams: an MFA enrolment flaw, a legacy ROPC grant or a misconfigured conditional access policy is a route past every other control.

darkmoon-licence.dmeDocker
LicencePro · annual
Machine code7F3A-…-C21E
Seats1 node
Statussealed ✓

Fintech ships daily, with ICT third parties everywhere

Infrastructure as code, Kubernetes, managed databases, core-banking SaaS, KYC providers: the surface moves with every release and DORA Articles 28-30 make the ICT third-party register your problem. Testing has to keep pace with the deployment cadence, not the audit calendar.

S.04Attack surface
The attack surface of a bank or fintech

Six system families Darkmoon enumerates and attacks, with the test accounts and sandboxes you provide. Production payment rails and card data environments are scoped explicitly during the scoping call.

Customer API
Web and mobile banking APIs

Authentication and session handling, object-level authorization on accounts, cards and beneficiaries, rate limiting on transfers and OTP endpoints, GraphQL and REST schema exposure, mobile API secrets.

Open banking
PSD2 account-information and payment-initiation endpoints

Consent lifecycle, third-party-provider registration, token scoping and redemption, replay of consent identifiers across customers, error handling that discloses account existence.

Payments
PSP webhooks, tokenization and batch exports

Signature verification of callbacks, idempotency of payment confirmations, exposure of SEPA or card batch files on transfer servers, acquirer and merchant portals, refund and chargeback workflows.

Identity / SSO
Customer IAM, SCA flows and back-office Entra ID

MFA enrolment and reset flows, OIDC configuration, conditional access gaps, legacy authentication grants, privileged roles of operations and treasury teams, service principals with standing credentials.

Cloud
AWS, Azure and GCP tenants of the entity

IAM policies and role chains, public storage and snapshots, secrets in Terraform state, Kubernetes clusters serving customer traffic, managed database exposure, logging and alerting blind spots.

CI/CD
Build pipelines and ICT third-party integrations

Pipeline tokens with production reach, artefact registries, Jenkins and GitLab runners, SaaS back-office integrations, KYC and fraud providers: the supply-chain side that DORA's third-party provisions put on the register.

S.05Attack paths

How an attacker reaches customer money and data.

Darkmoon chains findings into paths and keeps the evidence of each step. Four paths our agents look for in a financial estate, each one qualified EXPLOITED only when the exploitation is machine-verified on your test accounts.

01
From a consent flow to another customer's account

An account-information consent identifier that is accepted for a different customer's token, or an account reference that is not bound to the authenticated session: one test customer reads another test customer's balances and transactions. EXPLOITED, with the request pair kept as evidence.

How the engine works

S.06What Darkmoon tests
What Darkmoon tests in a financial entity

Three engagement shapes, each run by an orchestrator and specialist agents behind an MCP gateway with a build-enforced allow-list of 142 tools. Scope, sandboxes and the exclusion of live payment rails are fixed in the e-signed framework.

web, API, mobile
FindingsCVSS
SQL injection9.8
SSRF to metadata9.1
Broken access control8.7
JWT signature bypass7.5
Path traversal6.9

Customer-facing APIs and open banking

Web and mobile banking APIs, PSD2 endpoints, onboarding and KYC flows, customer portals. Web and API agents with your test customers and sandbox TPP credentials; authorization matrices, consent handling, rate limiting, business-logic abuse on transfers and beneficiaries.

cloud, Entra ID, pipelines
$darkmoon run --scope identity
→AS-REP roast · 3 accounts
→Kerberoast · svc_sql cracked
→NTLM relay → DCSync
✓Domain Admin, proven

Cloud, identity and CI/CD

AWS, Azure or GCP tenants, Entra ID and OIDC configuration, Kubernetes clusters, Terraform state, pipeline tokens and artefact registries. The route from a developer secret to the production account, mapped on the infrastructure graph.

AD, internal apps
Attack surfaceexposure

Internal estate and back-office

From an assumed-breach foothold: Active Directory, treasury and operations applications, databases and message brokers behind the APIs, internal admin consoles, AI assistants and MCP servers used by support teams (OWASP LLM Top 10).

S.07How an engagement works

From order to report, in five steps.

A process designed to be simple for the client and rigorous on the security side.

01
Describe your target

A guided form: target type, scope and objectives.

How the engine works

S.08Evidence & reporting
Concrete, actionable deliverables.

Not just an automated scan: a structured, validated and debriefed audit.

ranked
FindingsCVSS
SQL injection9.8
SSRF to metadata9.1
Broken access control8.7
JWT signature bypass7.5
Path traversal6.9

Detailed pentest report

Vulnerabilities ranked by severity, technical evidence, business impact and prioritized remediation guidance.

email + OTP
New engagement
Targetapp.acme.test
Scopeweb · API · cloud
Window5 business days
Flat rate€799

Secure client space

Access by email and OTP code. Contractual documents, report and exchanges centralized, available whenever you need them.

video call
Attack surfaceexposure

Debrief meeting

A video call with an expert to walk through the findings, answer questions and guide you on the fixes.

S.09Where your data goes
Your data stays on your side of the line.

The Privacy Gateway tokenizes every sensitive value (IPs, hostnames, URLs, emails, credentials, internal paths) on your machine before anything reaches the model, and rehydrates it locally. Self-host the whole engine with a local LLM, or let our experts run the managed engagement: in both cases the evidence stays in a space you control.

S.10Regulatory context
DORA, PCI DSS and where NIS2 still applies

Financial entities have a resilience-testing regime of their own: DORA. Card-data environments add the PCI DSS penetration testing requirement, internal and external testing of the cardholder data environment and its segmentation; Darkmoon is not an Approved Scanning Vendor and does not replace the quarterly ASV scans. Darkmoon does not certify compliance; it produces documented, reproducible findings you can present to your management body, auditors or supervisory authority as part of your evidence base.

DORA governs financial entities, not NIS2: Articles 24 and 25

NIS2 Article 4 gives way to sector-specific Union acts with at least equivalent risk-management and incident-notification duties, and Article 2(10) excludes entities exempted from DORA. Regulation (EU) 2022/2554 applies since 17 January 2025 to the entities of its Article 2(1), credit, payment and e-money institutions, investment firms, crypto-asset service providers, insurers and the other listed types, regardless of size, with proportionality. Article 24 requires a resilience testing programme with tests at least yearly on ICT systems supporting critical or important functions, by independent testers; Article 25 lists the required test types and names penetration testing among them. Darkmoon's qualified findings, evidence, JSON and PDF reports, CVSS 3.1 and ISO 27001 mapping are built to feed that programme.

PCI DSS v4: the penetration testing requirement

Entities that store, process or transmit cardholder data follow PCI DSS, a contractual standard of the PCI Security Standards Council rather than a law. Its penetration testing requirement asks for internal and external testing of the cardholder data environment and of the segmentation that isolates it. Darkmoon can test the systems in and around that environment with the scope and segmentation controls agreed in the framework; it is not an Approved Scanning Vendor, so the quarterly external ASV scans remain a separate obligation.

TLPT (Articles 26-27): a supervised regime Darkmoon does not replace

Threat-led penetration testing is required at least every three years for the entities their authority identifies, on live production systems, with a scope validated by the authority, testers meeting Article 27 requirements and an attestation at the end. Darkmoon is not a DORA TLPT. It supports the general programme and produces evidence you may bring to the TLPT scoping; the TLPT itself stays with your authority and external testers.

Where NIS2 still appears: Annex I, points 3 and 4

NIS2 Annex I names Banking (“Credit institutions as defined in Article 4, point (1), of Regulation (EU) No 575/2013”) and Financial market infrastructures (operators of trading venues, central counterparties). An entity of a listed type is in scope when it is at least a medium-sized enterprise: 50 staff or more, or an annual turnover AND balance-sheet total above €10 M; essential entities are the large ones, 250 staff or more, or turnover above €50 M and balance sheet above €43 M; plus the size-independent cases of Article 2(2) and Article 3. In practice DORA takes precedence for these entities. The French bill transposing CER, NIS2 and the DORA directive is not promulgated (Assemblée nationale session scheduled 7 October 2026).

Darkmoon does not certify compliance. This section is general information, not legal advice, and reflects the texts as of 4 October 2026; whether an entity falls under DORA, NIS2 or both is for its legal and compliance teams and its supervisor to establish.

S.11Use case
A payment institution preparing its yearly DORA testing cycle

The CISO of a payment institution has to show its management body that the systems supporting its critical functions were tested this year by an independent party. The scoping call sets the frame: the customer API and the PSD2 endpoints in the sandbox environment with test customers, the Azure tenant and the GitLab pipelines in read-only, the live payment rail and the card-data environment excluded, business hours avoided. Darkmoon's agents attack the APIs, map the identity and cloud estate and chain the findings into paths.

Outcome

A report ranked by severity with the evidence of each step, a CVSS 3.1 score and an ISO 27001 mapping per finding, the infrastructure graph of the route from a pipeline secret to the production tenant, and a debrief with the CISO and the head of engineering. The institution files it as one piece of its Article 24 testing evidence and keeps the TLPT question, if its authority raises it, as a separate exercise.

Pentest on Demand
€799/ engagement
  • Full penetration test on the defined scope
  • Legal framework and authorizations included
  • Detailed report with evidence and recommendations
  • Secure client space with OTP access
  • Video debrief meeting with an expert
  • Personalized scoping by our team
S.12Pricing

A clear flat rate, shown upfront.

The price is known before payment. No quote, no surprise. Indicative price, adjusted to the final scope. If the scoping call changes the scope and the price, you are told before anything starts.

Legal framework & authorizations included

S.13Frequently asked
What a bank or fintech CISO asks first.

Is Darkmoon a DORA TLPT?

No. A threat-led penetration test under Articles 26-27 is run on live production, on a scope validated by your competent authority, by testers meeting Article 27 requirements, and ends with an attestation. Darkmoon supports the general testing programme of Articles 24-25 and gives you qualified findings and evidence; it does not replace the TLPT.

Does DORA require penetration testing?

Article 25 lists penetration testing among the tests a financial entity's resilience testing programme must include, and Article 24 requires tests at least yearly on ICT systems supporting critical or important functions, by independent testers. Microenterprises benefit from proportionality. How you assemble that programme is your decision; Darkmoon is one of the inputs.

Can it cover the PCI DSS penetration testing requirement?

PCI DSS asks for internal and external penetration testing of the cardholder data environment and of its segmentation controls. Darkmoon can test the systems in and around that environment with the scope and segmentation controls agreed in the framework. It is not an Approved Scanning Vendor, so the quarterly external ASV scans remain a separate obligation.

NIS2 or DORA: which one applies to us?

If you are a financial entity listed in DORA Article 2(1), DORA governs your ICT risk management and incident reporting; NIS2 Article 4 gives way to it as lex specialis. Credit institutions and financial market infrastructures still appear in NIS2 Annex I, but in practice DORA takes precedence. Your legal team and your supervisor settle the question; Darkmoon does not.

Can we run it inside our own perimeter?

Yes. The Community edition is GPLv3 and self-hosting is the default; you can pair it with a local LLM via Ollama or llama.cpp. The Privacy Gateway tokenizes IPs, hostnames, URLs, emails and credentials on your machine before anything reaches the model, and rehydrates them locally. Pro adds the hardened sealed runtime, AES-256 storage and one-command cloud deploy.

What evidence do we get for our auditors and our supervisor?

Findings qualified EXPLOITED, CONFIRMED or UNCONFIRMED by an adversarial rubric, with the requests, payloads and screenshots kept; JSON and Markdown reports, branded PDF and web reports with CVSS 3.1, MITRE ATT&CK and ISO 27001 mapping in Pro. Darkmoon does not certify compliance; the report is evidence you present, not an attestation.

We are a fintech. Can this run in CI/CD on every release?

Yes. GitHub Actions, GitLab CI/CD and Jenkins integrations are available, with the scheduler for recurring campaigns and the remediation agent in Pro: it opens sandbox-validated fix pull requests for human review, never auto-merged. That cadence is what a yearly test cannot give you between two releases.

What do we need to provide?

A written authorization for the targets in scope (the legal framework you sign at order time), the URLs, hostnames or network ranges to test, test accounts where authenticated testing matters, and a contact for the scoping call. Our experts confirm the scope and the constraints with you before the engagement starts.

Can we share the report with our insurer, clients or auditors?

Yes. The report is yours. It documents each finding with its evidence, severity and remediation guidance, so it can be handed to a cyber-insurer, a client's procurement team or an auditor as a dated, factual description of what was found. It is evidence, not a certification.

What happens after the report?

You get a prioritised fix list with the evidence for each finding, a debrief call to walk through it, and the option to retest once the fixes are in. Teams that self-host can schedule recurring campaigns (Pro) so the same checks run after each change; the Pro remediation agent can also open sandbox-validated fix pull requests for your developers to review.

S.14Related
Go deeper

S.15Next
Feed your testing programme with exploitation evidence, not scan output.

Describe your APIs, tenants and pipelines, sign the framework online and get a report your management body can read. The TLPT stays with your authority; the rest of the programme can start this week.