All integrations
Amass logo
// Tentacle Tool · OSINT

Cracken + Amass

Cracken runs OWASP Amass to expand one seed domain into the sibling root domains its registrant holds and the subdomains that resolve under each. It carries that whole footprint forward in the same operation.

Get started
// 01

Connecting Amass

Connect with

No credentials — runs on your own Tentacle

Cadence

Runs on demand — installed on a Tentacle, then invoked during an operation (the agent can install and uninstall it mid-run)

Requires

A Tentacle running Linux or macOS. Free licence, nothing to purchase and no credentials to supply.

// 02

What Cracken gets from Amass

  • FQDN assets — apex domains, subdomains, CNAME, SRV and TXT records

  • IPAddress assets, resolved forward and from reverse DNS sweeps

  • Netblock, AutonomousSystem and AutnumRecord assets (ASN and BGP routing data)

  • DomainRecord assets — WHOIS registration data, with privacy-protection detection

  • ContactRecord and EmailAddress assets pulled from registration records

  • TLSCertificate assets and JARM fingerprints for the hosts it probes

  • URL assets and Service banners from HTTP probing

  • Organization and Location assets from horizontal correlation

// 03

What Amass does not do

Amass only enumerates and correlates. Nothing in it tests, authenticates against or exploits what it finds. Cracken supplies no API keys, so the keyed sources in Amass's data-source list — Shodan, VirusTotal, PassiveTotal, IntelX and the rest — run unconfigured.

// 04

How Cracken uses Amass

  1. 01

    Install Amass on a Tentacle

  2. 02

    Give the operation a seed

  3. 03

    Work what Amass returns

  4. 04

    Confirm the Tentacle is ready

// 05

Frequently asked questions

Do I have to install Amass myself to use it with Cracken?

No; Amass installs onto a Tentacle from the Integration Center, by an operator or by Cracken's agent mid-operation, and needs no licence.

Where does Amass run, and what leaves my environment?

Amass runs inside a Tentacle, a Kali Linux container on infrastructure you control, so its DNS, certificate, and OSINT requests leave from that host.

“I've been pretty impressed with how CrackenAGI is able to do its vulnerability discovery, enumeration, reconnaissance, as well as eventually being able to actually execute different exploitation paths.”

Cybersecurity Engineer, red team · test-and-measurement manufacturer

Attack with real Amass context.

See how Cracken runs Amass on a Tentacle you host, and proves what it finds end to end.