Reachability, not the segmentation diagram
Walks the credential and network paths between the corporate zone and the systems bordering control, and reports where each route was stopped short of the control network.

No PLC, HMI or SCADA is touched — this run stays IT-side. What comes back is the path, the credentials that opened it, and the line where the run stopped.
IT/OT boundary validation proves by execution how far an attacker who already holds a corporate foothold can move toward the industrial control network. It walks the credential and network paths between the zones on the live estate and records where each route stopped.
Walks the credential and network paths between the corporate zone and the systems bordering control, and reports where each route was stopped short of the control network.
Targets are authorised before the run starts, approval on every command is the default, and the run stops at the last IT-side host.
Runs the tradecraft behind real infrastructure intrusions, with technique IDs recorded on the operation graph as the run goes.
The operation ledger holds each command, its result and the artifacts it produced: an audit trail of the whole path and a stated stop line.
The operator logs in with your own credentials, works with your own admin tools, and waits at the boundary. Five stages, and the one where an authorised run stops.
Logs in with valid accounts. No exploit, no malware.
Enumerates what actually answers on your authorised external ranges, and tests which of those entry points accept credentials.
Uses the admin tooling already on the host, so there is nothing to signature.
Runs the same native-tool tradecraft from an installed Tentacle and logs every command, so your team can match it against what detection saw.
Dumps the domain database and reuses what it finds.
Reproduces the domain attacks against the live directory — roasting, ADCS abuse, delegation, coercion and relay — and records only the credentials it actually obtained.
Moves toward the systems that border OT.
Attempts the crossing with the credentials the run already proved, and records where each route was stopped short of the control network.
Sits on the boundary and waits for the moment to disrupt.
Stops at the last IT-side host and hands over the ledger. Nothing touches a PLC, an HMI or SCADA.
The external domains and ranges in scope, one corporate segment with a Tentacle on a host inside it, and the Windows domain behind them. Nothing on the control side is a target. The run stops at the last IT-side host.
Written from the execution plan of the playbooks that run today — Domain Recon, Web App Pentest, Network Pentest, Cloud Pentest, AD Pentest. A run covers the target you authorise, under the policy you set.
Enumerate the authorised domains and external ranges: subdomains, certificate history, resolving hosts, then the open ports, services and versions on each public IP.
Domain Recon playbook — shipsWhich addresses in scope actually answer from the internet, and what is behind each one — as opposed to what the asset inventory lists.
Install a Tentacle on a host in the corporate segment. Discover hosts, enumerate services and versions, test what answers, and read the firewall rules and ACLs meant to contain them.
Network Pentest playbook — shipsWhat a first foothold reaches inside the network, and which containment rules are enforced rather than documented.
Work the domain from that foothold: Kerberos roasting, ADCS abuse, delegation, ACL and GPO abuse, coercion and relay, cross-forest trusts. Every credential is reproduced against the live domain before it is recorded.
Active Directory Pentest playbook — shipsWhich identities a corporate foothold can obtain, proven by reproduction rather than inferred from a path map.
From the segments those credentials open, attempt the crossing into the next segment toward the control network, and record where the attempt was stopped.
Network Pentest playbook — shipsWhether the segmentation between corporate IT and the systems bordering control holds against credentials the run already proved.
Stop at the last IT-side host. Hand over the operation ledger: every command, every result, every artifact, with ATT&CK technique IDs recorded on the graph.
Operation ledger — shipsAn audit trail of the whole path and a stated stop line.
What this did not prove: The run proves nothing about the control network itself. No PLC, HMI or SCADA is contacted, and no OT-side control is tested. Where it stops is a scope decision, not a control that held — whether that last host can actually reach a controller is left open.
A state operator has already run this against a utility like yours. Ask a general-purpose model for the same living-off-the-land tradecraft and it declines; Cracken's model writes it under authorisation, and the run still stops at the last IT-side host.
Living-off-the-land tradecraft with the admin tools already on the host, so there is no malware for a signature to catch.
Builds the credential path from a first foothold to the segments that border control.
Writes the tooling for the crossing attempt against your live estate, then stops at the last IT-side host and records where it was stopped.
No. This run is scoped to the IT side: Domain Recon, Web App Pentest, Network Pentest, Cloud Pentest and Active Directory Pentest. An authorised run stops at the last IT host before the control network and records where it stopped.
It tests what answers, not what is listed. CISA told the water sector the same thing on 30 July 2026: "Even water organizations with mature cybersecurity processes should validate their external connections, as this targeting activity includes cellular modems installed by operators, vendors, or system integrators that may not be documented or included in routine attack surface scans." A run enumerates the authorised ranges and reports the service and version behind every port that responds. — CISA Urges Water and Wastewater Systems Sector to Protect OT Against Activity Targeting PLCs (Cybersecurity and Infrastructure Security Agency (CISA), 2026-07-30)
Partly, and only on the IT side. Advisory AA26-097A, issued by the FBI, CISA, NSA, EPA, DOE, CNMF and Treasury and last revised 22 July 2026, describes actors disrupting internet-connected OT devices across Government Services and Facilities, Water and Wastewater Systems and Energy, "resulting in operational disruption and financial loss." An authorised Cracken run establishes which addresses in your external ranges answer and how far a corporate foothold travels toward the boundary. It does not interact with a PLC. — AA26-097A: Iranian-Affiliated Cyber Actors Exploit Programmable Logic Controllers Across US Critical Infrastructure (Originally published 2026-04-07, last revised 2026-07-22, FBI, CISA, NSA, EPA, DOE, CNMF and Treasury, 2026-07-22)
No. The published evidence is research, not customer results: the team's paper "Red-Teaming the Agentic Red-Team" (arXiv:2606.24496, 23 June 2026) reports a security analysis spanning twelve agentic tools, with code execution achieved in 97.8% of runs aggregated across ten agentic red-teams, and Project BlackSea, an open-source honeypot published under Apache-2.0. — Red-Teaming the Agentic Red-Team (Pasquini, Bazyli, Fedynyshyn, Sorokin) (arXiv:2606.24496, arXiv, 2026-06-23)
Nobody needs to be on site once the Tentacle is installed on a host in the target segment, and the same scope can be re-run after a firewall change from wherever your team sits. Targets are authorised before the run starts and nothing acts outside that list. Approval on every command is the default until you raise the ceiling, and the run can be stopped at any point.
Cracken deploys self-hosted, which is what regulated operators usually require. For self-hosted and sales-managed workspaces, model training is disabled, so workspace content is not used for model improvement. That statement is scoped to those two workspace types and does not extend to every plan — check the scope against the plan you buy.
Tentacles, the Cybergraph, the approval gate every action passes through, and the operation ledger that records what ran. Critical infrastructure is one playbook on top of that engine.
One playbook answers one question. The case for validating exposure at all — why a scanner score is not a finding, and what changes when something proves the path instead of ranking it — is the argument this page assumes.
This playbook tests the one network you have never run an attacker at, only as far as a limit you set first.
This playbook tells you which stages of that actor's chain your controls stop, and which they do not.
Why a click rate tells you who fell for it, and what a real lure would have taken.
The case for attacking your open findings instead of ranking them, and which playbooks do it today.
You get the list of internet-facing assets you actually expose, including the ones no inventory has.
You get the paths to Domain Admin that actually hold, and the command that proved each one.
Scope a run that stops at the IT side of the boundary.
Cookie Consent
We use cookies to enhance your browsing experience, analyze site traffic, and personalize content.