# Cracken > Cracken is an AI-driven adversarial exposure validation platform: autonomous agents that attack your infrastructure the way real adversaries do, so you can validate and fix what actually matters. Five playbooks execute today; eight further capabilities are sold as modules that do not run yet, and each is marked below. ## Playbooks that execute - [External Attack Surface Discovery](https://cracken.ai/use-cases/attack-surface-discovery): You get the list of internet-facing assets you actually expose, including the ones no inventory has. - [Autonomous Web Application Penetration Testing](https://cracken.ai/use-cases/web-app-pentest): You get working exploits against your own web application, each one reproduced before anyone wrote it down. - [Internal Network Penetration Testing](https://cracken.ai/use-cases/network-pentest): You learn which internal hosts one foothold reaches, and where the boundary stopped it. - [Cloud Penetration Testing](https://cracken.ai/use-cases/cloud-pentest): You learn which cloud identities actually reach production data, and the exact role chain each one walks to get there. - [Active Directory Attack Path Validation](https://cracken.ai/use-cases/active-directory-pentest): You get the paths to Domain Admin that actually hold, and the command that proved each one. ## Practice and category pages No playbook sits behind these. They cover the market category Cracken sells into, and tradecraft an investigator runs with tooling rather than an orchestrated playbook. - [Adversary Simulation & Threat Actor Emulation](https://cracken.ai/use-cases/adversary-simulation): This playbook tells you which stages of that actor's chain your controls stop, and which they do not. - [AI Penetration Testing Platform](https://cracken.ai/use-cases/ai-penetration-testing): This playbook hands your engineers exploits they can re-run, not a list of things that might be exploitable. - [Social Engineering Reach Testing](https://cracken.ai/use-cases/spear-phishing): Why a click rate tells you who fell for it, and what a real lure would have taken. - [Adversarial Exposure Validation (AEV)](https://cracken.ai/use-cases/adversarial-exposure-validation): The case for attacking your open findings instead of ranking them, and which playbooks do it today. - [Application Vulnerability Validation](https://cracken.ai/use-cases/application-security): This playbook cuts the application security backlog down to the findings an attacker can actually reach. - [Social Engineering Testing](https://cracken.ai/use-cases/social-engineering): This playbook shows which channel gets a stranger through, and which procedure let them. - [Threat Intelligence Validation](https://cracken.ai/use-cases/threat-intel): This playbook separates the threat-feed items usable against you from the ones you can stop carrying. - [Malware Analysis & Isolated Detonation](https://cracken.ai/use-cases/malware-research): This playbook establishes what a file does on a host you own, without giving custody of the sample to anyone. - [Digital Forensics & Host Artifact Analysis](https://cracken.ai/use-cases/digital-forensics): This playbook shows how much of a real attack your hosts recorded, when you already know what was done to them. - [OT & ICS Penetration Testing](https://cracken.ai/use-cases/ot-ics-security): This playbook tests the one network you have never run an attacker at, only as far as a limit you set first. - [Sock Puppet OPSEC for OSINT Investigations](https://cracken.ai/use-cases/research-account-opsec): A research account that does not resolve back to you, and an exit address that is revocable and on the record. - [OSINT Username and Email Pivot Tools for Investigations](https://cracken.ai/use-cases/osint): Sixteen collection tools on one Tentacle, and a ledger of which command hit which selector. No identity is resolved for you — the join from handle to human is yours to argue. ## Industries - [AI Infrastructure Penetration Testing](https://cracken.ai/industries/ai-companies) - [DORA Threat-Led Penetration Testing for Banks](https://cracken.ai/industries/banking-fintech): DORA threat-led penetration testing (TLPT) - [IT/OT Boundary Validation for Critical Infrastructure](https://cracken.ai/industries/critical-infrastructure): IT/OT boundary validation - [Nation-State Adversary Emulation for Government & Defense](https://cracken.ai/industries/government-defense): nation-state adversary emulation - [Healthcare Ransomware Exposure Validation](https://cracken.ai/industries/healthcare) - [DORA Threat-Led Penetration Testing for Insurers](https://cracken.ai/industries/insurance): DORA threat-led penetration testing (TLPT) for insurers - [FDA Premarket Medical Device Penetration Testing](https://cracken.ai/industries/pharma-life-sciences) - [Multi-Tenant Isolation Testing for SaaS](https://cracken.ai/industries/technology-saas): multi-tenant isolation testing - [Telecom Network Penetration Testing](https://cracken.ai/industries/telecoms) ## Platform - [Platform](https://cracken.ai/platform): How the operating engine, Workers and the Cybergraph fit together - [Pricing](https://cracken.ai/pricing): Plans and prices, anchored against what each replaces - [Integrations](https://cracken.ai/platform/integrations): Security stack integrations the platform connects to - [Playbooks](https://cracken.ai/use-cases): What a playbook is as an object, and which ones run - [Industries](https://cracken.ai/industries): The sector threat each page is anchored against, and where a run stops ## Lab - [Model](https://cracken.ai/lab/model): Research on Cracken's offensive security model - [BlackSea](https://cracken.ai/lab/blacksea): Cracken Lab's adversarial cyber range research ## Resources - [Blog](https://cracken.ai/blog): Articles on adversarial validation and offensive security - [Press](https://cracken.ai/resources/press): Press coverage and announcements - [Events](https://cracken.ai/resources/events): Upcoming and past Cracken events - [Webinars](https://cracken.ai/resources/webinars): Recorded and upcoming webinars - [Regulatory Storm](https://cracken.ai/resources/regulatory-storm): Incoming security regulation, tracked ## Company - [Demo](https://cracken.ai/demo): Request a product demo - [Sign up](https://cracken.ai/free-trial): Create a Cracken account - [About](https://cracken.ai/about): The team and mission behind Cracken - [Partners](https://cracken.ai/partners): The Cracken partner program - [Handbook](https://cracken.ai/partners/handbook) - [Legal](https://cracken.ai/legal): Privacy policy, terms, and other legal documents