Walk the crew's route to domain control
External foothold, domain enumeration, lateral movement, escalation — the shipped Network Pentest and AD Pentest playbooks run end to end.

The run fires no ransomware and stages nothing on live clinical systems. Imaging, infusion, and monitoring fleets are reached by network position.
Healthcare ransomware exposure validation runs an authorised offensive operation against a health system's live estate — remote access, Active Directory, EHR integrations, connected devices — to prove which paths a ransomware crew could take to patient records and clinical systems, and where each one stops.
External foothold, domain enumeration, lateral movement, escalation — the shipped Network Pentest and AD Pentest playbooks run end to end.
Follows the credentials recovered along the way to the systems holding PHI — EHR integrations, file shares, cloud stores — and records exactly what opened.
Shows whether segmentation around imaging, infusion, and monitoring fleets holds, and which of them a proven path reaches.
An intrusiveness ceiling and a full ledger keep the run off live care. It fires no ransomware and detonates nothing.
It started with one remote-access box missing MFA. Nine days later, a network held hostage. Walk each step.
Logs into a remote box with no MFA.
Network Pentest hunts your remote access for the same missing factor, then proves entry.
Spreads quietly for days.
AD Pentest maps the domain and works the same path to domain control.
Exfiltrates PHI, SSNs, records.
Proves the route to the records store and the credentials that open it. It removes no patient data.
Fires ransomware, care stops.
The intrusiveness ceiling ends the run at the proven path: it fires no ransomware and detonates nothing.
You pay, or rebuild while patients wait.
Hands over the proven path and the loot recovered, before a crew does.
One internet-facing remote-access service without MFA, the Active Directory domain behind it, and the systems holding patient records — the route in most reported health-system ransomware intrusions.
Written from the execution plan of the playbooks that run today — Domain Recon, Web App Pentest, Network Pentest, Cloud Pentest, AD Pentest. A run covers the target you authorise, under the policy you set.
External foothold
Network Pentest playbook — discovery, port and service enumeration, exploitationAn internet-facing remote-access service reachable without MFA becomes a working entry point.
Domain enumeration
AD Pentest playbook — discovery sub-operation (ad-discovery skill, cyber-graph)From the foothold identity, the domain, its DCs, users, ACLs and trusts are mapped into the attack graph.
Lateral movement and escalation
AD Pentest playbook — exploit fan-out (Kerberoasting, ACL abuse, delegation, ADCS)A path from the foothold to domain control is worked technique by technique and escalated toward Domain Admin.
Reach the records store
AD Pentest playbook — verify sub-operation reproduces each credential and accessThe proven credentials open the route to the systems holding patient records — the objective a ransomware crew is paid to reach.
Stop before detonation
Findings recorded only after a separate verification step reproduces the accessThe run records the proven path and the recovered loot. It fires no ransomware and detonates nothing.
What this did not prove: The run fires no ransomware and stages nothing on live clinical systems. Cracken has no signed healthcare customer, so no figure here comes from one.
Cracken's model was trained for offense, and the removal is domain-scoped: published research puts its cyber-domain refusal at 7%, down from 100%, with explicit-content refusal held at 100% and other domains at 44-88%. Downtime in your network is a patient-safety event — so the operator gets working exploitation on your estate, in scope, under a ledger, and never the event itself.
Writes the working exploit for the remote-access box missing MFA and proves entry on your estate, under authorisation.
Builds the crew's nine-day lateral path to the records store inside a single authorised run.
Works Kerberoasting, ACL abuse, delegation and ADCS until the route to Domain Admin is proven, then reproduces every credential before it is written down.
Errol Weiss, Chief Security Officer at Health-ISAC, put it on the record: "The Health sector has become one of the most targeted sectors in the world, not because it's the easiest, but because the consequences of disruption are so severe. This report is a clear warning: cyber threats are no longer isolated events. They represent life-saving business continuity crises that can impact patient care, staff safety, and public trust." The same 2026 report tracked 455 ransomware incidents globally targeting health organizations, with Qilin, INC Ransom, and SAFEPAY among the most active. — Health-ISAC 2026 Annual Threat Report — announcement release (Health-ISAC (via GlobeNewswire), 2026-01-26)
Because the path in often runs through someone else. Health-ISAC's 2026 finding is blunt: "Even organizations with strong internal security may remain vulnerable through a partner, platform, managed service provider, or widely used software solution." A validation run follows those inherited paths — remote access, EHR integrations, trusted vendors — and proves which ones actually reach patient data, rather than assuming a hardened core keeps them out. — Health-ISAC 2026 Annual Threat Report — announcement release (Health-ISAC (via GlobeNewswire), 2026-01-26)
That is what the defined scope and the intrusiveness ceiling exist for. The run recovers credentials and proves the route to the records store; it fires no ransomware and stages nothing on live clinical systems. Downtime in a health network is a patient-safety event — ENISA records ransomware attacks against two German organisations that resulted in the postponement of medical procedures — so the operation proves the path without causing the outcome. — ENISA Threat Landscape 2025, §6.2 (v1.2 (revised 2026-01-09), European Union Agency for Cybersecurity (ENISA), 2025-10)
A scan lists weaknesses; this proves the chain. Cracken runs the shipped Network Pentest and AD Pentest playbooks end to end — external foothold, domain enumeration, lateral movement, escalation to domain control — and records a finding only after a separate verification step reproduces the access. You get the proven route to patient records, with the credentials recovered along the way, not a ranked inventory of things that might matter.
Yes, by network position. The network and Active Directory paths that reach imaging, infusion, and monitoring fleets are covered by the shipped Network Pentest and AD Pentest playbooks — a device on a reachable, flat segment shows up as part of the proven path, with the credentials recovered along the way.
Tentacles, the Cybergraph, the approval gate every action passes through, and the operation ledger that records what ran. Healthcare is one playbook on top of that engine.
One playbook answers one question. The case for validating exposure at all — why a scanner score is not a finding, and what changes when something proves the path instead of ranking it — is the argument this page assumes.
This playbook tells you which stages of that actor's chain your controls stop, and which they do not.
Why a click rate tells you who fell for it, and what a real lure would have taken.
The case for attacking your open findings instead of ranking them, and which playbooks do it today.
You get the list of internet-facing assets you actually expose, including the ones no inventory has.
You get the paths to Domain Admin that actually hold, and the command that proved each one.
This playbook shows which channel gets a stranger through, and which procedure let them.
Scope a run against a non-clinical environment first.
Cookie Consent
We use cookies to enhance your browsing experience, analyze site traffic, and personalize content.