Cracken shows what CrowdStrike Falcon caught and missed against real attacks.
Connect your stack.
Attack it with real context.
Every tool you run feeds one operation — Cracken proves what an attacker can reach.
Data integrations
The security tools you run — Cracken reads and attacks their findings.
Cracken attacks Tenable findings in scope to prove which ones an attacker reaches.
Cracken queries your GitHub repositories and their scanning and Dependabot alerts live.
Cracken queries your Qualys detections live and launches a fresh scan when needed.
Cracken reads Okta users and groups live into the identity map it attacks.
Cracken attacks Wiz findings in your cloud accounts to prove which reach impact.
Cracken proves which Aikido issues an attacker can reach from outside.
Cracken proves which Amazon Inspector findings an attacker can actually reach.
Cracken proves which CrowdStrike Spotlight vulnerabilities are exploitable on those hosts.
Cracken queries your GitLab projects and vulnerability findings mid-operation.
Cracken proves which Microsoft Defender for Cloud recommendations an attacker can exploit.
Cracken attacks your devices, then names which techniques Microsoft Defender for Endpoint caught.
Cracken proves which Microsoft Defender Vulnerability Management weaknesses an attacker can use.
Cracken attacks Microsoft Entra ID identities to prove which reach Global Administrator.
Cracken proves which Orca Security findings an attacker can reach on the running workload.
Cracken attacks Rapid7 InsightVM findings to prove which ones an attacker reaches.
Cracken attacks your endpoints, then reads what SentinelOne flagged, blocked, and missed.
Cracken syncs SentinelOne VM's CVE findings and attacks the endpoints they cover.
Cracken queries Shodan mid-operation for a host's services and CVEs.
Cracken attacks the running app to prove which Snyk findings are reachable.
Tentacle tools
Offensive binaries Cracken installs on a Tentacle and drives itself.
Cracken drives ffuf on a Tentacle to brute-force hidden endpoints, then attacks them.
Cracken runs httpx from a Tentacle to find live hosts and their technology.
Cracken runs Katana from a Tentacle to map every route a site exposes.
Cracken builds a username dossier with Maigret, then chases every identifier it scrapes.
Cracken runs Nuclei's YAML checks against in-scope hosts, then attacks the hits worth attacking.
Cracken drives OSINTgram from an Instagram session on your Tentacle to scrape a profile.
Cracken runs PhoneInfoga on a Tentacle to profile a number and chase its leads.
Cracken runs theHarvester on a Tentacle to gather a domain's emails and hosts.
Cracken runs Trivy on a reached image or host to find vulnerable packages.
FOCA
When it ships, Cracken will drive FOCA to harvest metadata from public documents.
When it ships, Cracken will run Subfinder from a Tentacle to map subdomains.
C2 tools
Command-and-control frameworks — catalogued, none shipping yet.
When it ships, Cracken will drive Brute Ratel's Badger implants across an operation.
When it ships, Cracken will drive Cobalt Strike's Beacon from your team server.
When it ships, Cracken will drive Covenant's in-memory Grunts across an operation.
When it ships, Cracken will drive Empire's modules as approval-gated stages.
When it ships, Cracken will drive Havoc's Demon agents as approval-gated operation stages.
When it ships, Cracken will win footholds with Metasploit and work from Meterpreter.
When it ships, Cracken will pick the right Mythic agent for each host.
When it ships, Cracken will drive Sliver's implants as approval-gated operation stages.
“…we’ve been continuously validating … the efficacy of Cracken with our own … pen tests, like external pen test findings. Just being sure that we could recreate those with Cracken. It’s been going good so far…”




























