Take the portal first
Runs injection, auth bypass, IDOR and file-upload attacks at the portal that manages the devices.

Authorised operations against the network-facing side of a connected-device programme: the portals that manage the devices, the cloud back end that receives their telemetry, and the lab and plant networks they sit on. Portal and directory findings are reproduced by a second operation before they are recorded.
FDA premarket medical device penetration testing is the exploit-driven testing a manufacturer submits with a 510(k), De Novo, or PMA. The FDA guidance issued 3 February 2026 fixes the report contents: tester independence and expertise, scope, duration, methods, and results. Vulnerability scanning is a separate item in the same guidance and does not stand in for it. — Cybersecurity in Medical Devices: Quality Management System Considerations and Content of Premarket Submissions (Final guidance, supersedes the 27 June 2025 edition, U.S. Food and Drug Administration (CDRH/CBER), 2026-02-03)
Runs injection, auth bypass, IDOR and file-upload attacks at the portal that manages the devices.
Turns a portal foothold into the role it can assume and the store of device and study data that role reads.
Tests whether segmentation around validated lab and manufacturing systems holds — up to the network interface, not the controller.
Scope, duration, methods and results come out of the operation ledger as the run happens. Independence stays your statement to make.
APT10 broke managed service providers and rode their trusted access into client networks. Cracken runs the stages that sit inside your authorisation, and names the ones it does not run.
Breaks your CRO, CDMO, or MSP first.
Not run. A partner's estate is a separate target that needs the partner's written authorisation and a scope of its own.
Rides the partner's connection into your network.
A Tentacle on an authorised host in the segment that access lands in maps which hosts answer and which paths leave it.
Settles in and harvests credentials.
Enumerates the domain from an ordinary account and works the credential paths it implies.
Locates trial data, formulas, and device telemetry.
Cloud Pentest follows the foothold into the tenant and names the role it can assume and the store of device and study data that role reads.
Moves the research out as ordinary traffic.
The run ends at the proven path and what it reaches.
A connected-device programme: one device management portal, the cloud account that receives its telemetry, and one internal segment. Domains, hostnames and principals are illustrative.
Written from the execution plan of the playbooks that run today — Domain Recon, Web App Pentest, Network Pentest, Cloud Pentest, AD Pentest. A run covers the target you authorise, under the policy you set.
The Domain Recon playbook runs against the domains the programme publishes: passive DNS, certificate transparency, and host intelligence, merged into one asset set with provenance on every record. Nothing is sent to the target.
T1590 Gather Victim Network InformationThe public surface of the programme — subdomains, certificates, resolving hosts, and the open ports, services and known CVEs on each public IP, including the ones that never reached the asset register. A domain outside the realm allowlist stops the run.
One sub-operation per surface per attack class against the portal that manages the devices: injection, auth bypass, IDOR, file upload, API logic. Each candidate goes to a separate operation that starts in fresh context and tries to reproduce it.
T1190 Exploit Public-Facing ApplicationWhich exploits actually fire. A candidate is recorded only after an independent operation reproduces it and captures the signal. The rest are killed, with the reason written down.
The Cloud Pentest playbook works the account that receives device telemetry, starting from the access the portal foothold provides: identities, roles, trust relationships, and the storage the data lands in.
T1078.004 Valid Accounts: Cloud AccountsHow far one web foothold reaches into the tenant — which role it can assume, and which bucket or database of device and study data that role can read.
A Tentacle is installed on an authorised host in the segment where the lab and manufacturing systems sit. From there: host discovery, service and version enumeration, a read of the firewall rules and ACLs meant to contain the segment, then an attempt to cross into the next one.
T1046 Network Service DiscoveryWhether segmentation holds in practice, and where the attempt was stopped. Every command, result and artifact lands in the operation ledger; hosts and the paths between them go to the Cybergraph, where technique edges carry their ATT&CK IDs.
The AD Pentest playbook enumerates the domain from an ordinary user account and works the credential paths that enumeration implies, toward the accounts that administer validated systems.
T1087.002 Account Discovery: Domain AccountThe shortest credential path from a standard account to systems under change control — reported as a proven path, or as attempts that returned no signal, which are written up separately from findings.
What this did not prove: No step touched device firmware, radio stacks, embedded controllers or a PLC on a line — this run was scoped to the portal, the cloud account behind it and one internal segment, and stopped at the device's network interface. The run fills the penetration-test section of a submission. It does not stand in for the security risk assessment around it.
MITRE ATT&CK v19.0, April 2026Commercial models decline the offensive half of this work. Cracken's own research cut cyber refusal from 100% to 7% on a 1T-parameter model while explicit-content refusal held at 100%.
Injection, auth bypass, IDOR and file upload run against the authorised portal until one fires, and a separate operation in fresh context reproduces it before it is recorded.
Enumeration from an ordinary domain account, then the credential paths that enumeration implies, up to the accounts that administer validated systems.
The lab and plant segment is tested by attempting the crossing, not by reading the rule meant to prevent it.
It produces most of what the guidance lists. FDA's guidance on cybersecurity in medical devices, issued 3 February 2026, states: "Penetration testing. · The testing should identify and characterize security-related issues via tests that focus on discovering and exploiting security vulnerabilities in the product. Penetration test reports should be provided and include the following elements: · Independence and technical expertise of testers; · Scope of testing; · Duration of testing; · Testing methods employed; and · Test results, findings, and observations." Scope, duration, methods, results and findings come out of the operation ledger as the run happens. Independence and technical expertise is a statement you make about who ran the test. FDA does not clear tools, and Cracken is not an accredited laboratory. — Cybersecurity in Medical Devices: Quality Management System Considerations and Content of Premarket Submissions (Final guidance, supersedes the 27 June 2025 edition, U.S. Food and Drug Administration (CDRH/CBER), 2026-02-03)
Yes, across the programme the device sits in: the management and clinician portals under the Web App Pentest playbook, the cloud back end that receives telemetry under Cloud Pentest, the segment the devices and lab systems sit on under Network Pentest, and the directory that administers them under AD Pentest. Firmware, radio stacks and embedded controllers are covered by the OT/ICS and malware-research playbooks. Scope is fixed against a realm allowlist before anything runs.
Only what you authorise, and only at the intrusiveness you set. Targets are fixed against a realm allowlist before anything runs, and a target outside it stops the run. Approval on each command is the default until you raise the ceiling. Every command, result and artifact lands in the operation ledger, so the record a change-control reviewer wants is written while the run happens rather than reconstructed afterwards. Where change control forbids testing the qualified system, the Tentacle goes on the qualified non-production replica and the same scope runs there.
Cracken tests your side of it. A Tentacle placed on an authorised host in the segment a partner's access lands in shows what that access actually reaches: which hosts answer, which credential path leads out of that segment, and where the boundary stopped the attempt. The partner's own estate is a separate target that needs the partner's written authorisation and a scope of its own. Cracken will not run against a system you cannot authorise.
The original report, not a summary of one. FDA's 3 February 2026 guidance states: "For any third-party test reports, manufacturers should provide the original third-party report. For all testing, manufacturers should provide their assessment of any findings including rationales for not implementing or deferring any findings". A Cracken run outputs that artifact: the scope, the commands, the captured signal, and each finding with the evidence of the operation that reproduced it, plus what could not be proven, named separately from what was. The assessment of the findings, and the rationale for anything you defer, stays yours to write. — Cybersecurity in Medical Devices: Quality Management System Considerations and Content of Premarket Submissions (Cybersecurity Testing section, U.S. Food and Drug Administration (CDRH/CBER), 2026-02-03)
The evidence is published rather than asserted. The team's paper Red-Teaming the Agentic Red-Team reports: "Table 3 reports the attack success rate aggregated across the 10 agentic-red-teams. On average, code execution is achieved in 97.8% of runs." — alongside a security analysis spanning twelve agentic tools. Two public repositories are readable before you scope anything: Blacksea, an active honeypot for LLM-driven attackers, and RedLineBench, 153 grounded, single-turn offensive-security prompts scored on refusal and capability, where every target domain and public IP is a sinkhole Cracken owns. — Red-Teaming the Agentic Red-Team (arXiv:2606.24496) (arXiv — Pasquini, Bazyli, Fedynyshyn, Sorokin, 2026-06-23)
Tentacles, the Cybergraph, the approval gate every action passes through, and the operation ledger that records what ran. Pharma & life sciences is one playbook on top of that engine.
One playbook answers one question. The case for validating exposure at all — why a scanner score is not a finding, and what changes when something proves the path instead of ranking it — is the argument this page assumes.
This playbook tests the one network you have never run an attacker at, only as far as a limit you set first.
This playbook tells you which stages of that actor's chain your controls stop, and which they do not.
Why a click rate tells you who fell for it, and what a real lure would have taken.
The case for attacking your open findings instead of ranking them, and which playbooks do it today.
You get the list of internet-facing assets you actually expose, including the ones no inventory has.
You get the paths to Domain Admin that actually hold, and the command that proved each one.
Scope a run against the network around your validated systems.
Cookie Consent
We use cookies to enhance your browsing experience, analyze site traffic, and personalize content.