Healthcare

Prove the ransomware path to patient data before a crew runs it.

The proven route to patient records: where it reaches, and where it stops.

The run fires no ransomware and stages nothing on live clinical systems. Imaging, infusion, and monitoring fleets are reached by network position.

Definition

What is healthcare ransomware exposure validation?

Healthcare ransomware exposure validation runs an authorised offensive operation against a health system's live estate — remote access, Active Directory, EHR integrations, connected devices — to prove which paths a ransomware crew could take to patient records and clinical systems, and where each one stops.

Walk the crew's route to domain control

External foothold, domain enumeration, lateral movement, escalation — the shipped Network Pentest and AD Pentest playbooks run end to end.

Prove the reach to patient records

Follows the credentials recovered along the way to the systems holding PHI — EHR integrations, file shares, cloud stores — and records exactly what opened.

Reach the device fleets by network position

Shows whether segmentation around imaging, infusion, and monitoring fleets holds, and which of them a proven path reaches.

Safe around clinical systems

An intrusiveness ceiling and a full ledger keep the run off live care. It fires no ransomware and detonates nothing.

ALPHV / BlackCat against a US health payer (2024) — entered a remote-access service without MFA, moved laterally for days, stole data, then detonated.

The ransomware crew's playbook, before they run it

It started with one remote-access box missing MFA. Nine days later, a network held hostage. Walk each step.

  1. 1Initial access
    Attacker

    Logs into a remote box with no MFA.

    With Cracken

    Network Pentest hunts your remote access for the same missing factor, then proves entry.

  2. 2Lateral movement
    Attacker

    Spreads quietly for days.

    With Cracken

    AD Pentest maps the domain and works the same path to domain control.

  3. 3Data theft
    Attacker

    Exfiltrates PHI, SSNs, records.

    With Cracken

    Proves the route to the records store and the credentials that open it. It removes no patient data.

  4. 4Detonation
    Attacker

    Fires ransomware, care stops.

    With Cracken

    The intrusiveness ceiling ends the run at the proven path: it fires no ransomware and detonates nothing.

  5. 5Recovery
    Attacker

    You pay, or rebuild while patients wait.

    With Cracken

    Hands over the proven path and the loot recovered, before a crew does.

One run

A ransomware crew's route to patient data, proven and stopped short of detonation

One internet-facing remote-access service without MFA, the Active Directory domain behind it, and the systems holding patient records — the route in most reported health-system ransomware intrusions.

Written from the execution plan of the playbooks that run today — Domain Recon, Web App Pentest, Network Pentest, Cloud Pentest, AD Pentest. A run covers the target you authorise, under the policy you set.

  1. 01
    What ran

    External foothold

    Network Pentest playbook — discovery, port and service enumeration, exploitation
    What it established

    An internet-facing remote-access service reachable without MFA becomes a working entry point.

  2. 02
    What ran

    Domain enumeration

    AD Pentest playbook — discovery sub-operation (ad-discovery skill, cyber-graph)
    What it established

    From the foothold identity, the domain, its DCs, users, ACLs and trusts are mapped into the attack graph.

  3. 03
    What ran

    Lateral movement and escalation

    AD Pentest playbook — exploit fan-out (Kerberoasting, ACL abuse, delegation, ADCS)
    What it established

    A path from the foothold to domain control is worked technique by technique and escalated toward Domain Admin.

  4. 04
    What ran

    Reach the records store

    AD Pentest playbook — verify sub-operation reproduces each credential and access
    What it established

    The proven credentials open the route to the systems holding patient records — the objective a ransomware crew is paid to reach.

  5. 05
    What ran

    Stop before detonation

    Findings recorded only after a separate verification step reproduces the access
    What it established

    The run records the proven path and the recovered loot. It fires no ransomware and detonates nothing.

What this did not prove: The run fires no ransomware and stages nothing on live clinical systems. Cracken has no signed healthcare customer, so no figure here comes from one.

Mainstream models refuse the exploitation. Cracken's writes it.

Cracken's model was trained for offense, and the removal is domain-scoped: published research puts its cyber-domain refusal at 7%, down from 100%, with explicit-content refusal held at 100% and other domains at 44-88%. Downtime in your network is a patient-safety event — so the operator gets working exploitation on your estate, in scope, under a ledger, and never the event itself.

?

Take the foothold

Writes the working exploit for the remote-access box missing MFA and proves entry on your estate, under authorisation.

Compress the timeline

Builds the crew's nine-day lateral path to the records store inside a single authorised run.

Take the domain

Works Kerberoasting, ACL abuse, delegation and ADCS until the route to Domain Admin is proven, then reproduces every credential before it is written down.

Downtime on your network is a patient-safety event. Rehearse the attack that causes it, on your schedule.
Questions

What health-system security teams ask first

Why has healthcare become a top target for ransomware?

Errol Weiss, Chief Security Officer at Health-ISAC, put it on the record: "The Health sector has become one of the most targeted sectors in the world, not because it's the easiest, but because the consequences of disruption are so severe. This report is a clear warning: cyber threats are no longer isolated events. They represent life-saving business continuity crises that can impact patient care, staff safety, and public trust." The same 2026 report tracked 455 ransomware incidents globally targeting health organizations, with Qilin, INC Ransom, and SAFEPAY among the most active.Health-ISAC 2026 Annual Threat Report — announcement release (Health-ISAC (via GlobeNewswire), 2026-01-26)

We've hardened our internal security. Why validate the attack path at all?

Because the path in often runs through someone else. Health-ISAC's 2026 finding is blunt: "Even organizations with strong internal security may remain vulnerable through a partner, platform, managed service provider, or widely used software solution." A validation run follows those inherited paths — remote access, EHR integrations, trusted vendors — and proves which ones actually reach patient data, rather than assuming a hardened core keeps them out.Health-ISAC 2026 Annual Threat Report — announcement release (Health-ISAC (via GlobeNewswire), 2026-01-26)

Can this run without disrupting patient care?

That is what the defined scope and the intrusiveness ceiling exist for. The run recovers credentials and proves the route to the records store; it fires no ransomware and stages nothing on live clinical systems. Downtime in a health network is a patient-safety event — ENISA records ransomware attacks against two German organisations that resulted in the postponement of medical procedures — so the operation proves the path without causing the outcome.ENISA Threat Landscape 2025, §6.2 (v1.2 (revised 2026-01-09), European Union Agency for Cybersecurity (ENISA), 2025-10)

How is this different from our annual pentest and vulnerability scan?

A scan lists weaknesses; this proves the chain. Cracken runs the shipped Network Pentest and AD Pentest playbooks end to end — external foothold, domain enumeration, lateral movement, escalation to domain control — and records a finding only after a separate verification step reproduces the access. You get the proven route to patient records, with the credentials recovered along the way, not a ranked inventory of things that might matter.

Does this cover our connected medical devices?

Yes, by network position. The network and Active Directory paths that reach imaging, infusion, and monitoring fleets are covered by the shipped Network Pentest and AD Pentest playbooks — a device on a reachable, flat segment shows up as part of the proven path, with the credentials recovered along the way.

If you run the operation

See the engine underneath this.

Tentacles, the Cybergraph, the approval gate every action passes through, and the operation ledger that records what ran. Healthcare is one playbook on top of that engine.

If you own the risk

Start from the exposure, not the technique.

One playbook answers one question. The case for validating exposure at all — why a scanner score is not a finding, and what changes when something proves the path instead of ranking it — is the argument this page assumes.

See how far a ransomware crew gets in your network.

Scope a run against a non-clinical environment first.