Cracken + Amazon Inspector
Amazon Inspector infers from your AWS configuration which EC2 instances, container images, and Lambda functions are exposed. Cracken puts that inference to the test. It reaches for those resources over the network and reports which answered.
Connecting Amazon Inspector
- Connect with
AWS Access Key ID, Secret Access Key and Region for a dedicated IAM user (no console access) with the AmazonInspector2ReadOnlyAccess and AmazonEC2ReadOnlyAccess policies attached.
- Cadence
Syncs on a schedule — every 6 hours by default — and can be re-synced on demand via the Trigger Scan action.
- Requires
Amazon Inspector enabled in every AWS region Cracken should read; permission to create an IAM user and access key. Direct access keys only — the form does not accept a role ARN.
What Cracken gets from Amazon Inspector
Vulnerability Findings with name, description, severity and state (new, active, re-opened, fixed)
cve[] identifiers with cvss_base_score, cvss_vector and cvss_version
The resource{} object a finding sits on, filterable by resource_id and resource_type
port, protocol and service where Inspector reports network reachability
patchable plus a solution string, and first_seen / last_seen / state_updated_at
In the Cybergraph: a Device node CONTAINS a Finding node, which CONTAINS a cve: Vulnerability node
What Amazon Inspector does not do
Cracken does not scan your AWS account. It reads findings Amazon Inspector already produced, and the only thing it can send back is a request to re-sync; nothing suppresses, closes or re-rates a finding in Inspector. Resource type is a free-text filter, not a fixed list, so Cracken does not define which Inspector resource types come back.
How Cracken uses Amazon Inspector
- 01
Connect Amazon Inspector
- 02
Sync findings into the Cybergraph
- 03
Prove reachability by attacking
- 04
Confirm it connected
Frequently asked questions
What AWS permissions does the Amazon Inspector integration need?
It uses an AWS access key ID, secret access key, and region only to read Inspector findings, never to launch a scan or modify Inspector.
Does Cracken re-scan the resources Amazon Inspector already covers?
No; Cracken reads findings Inspector already produced, re-pulling rather than scanning, then attacks the affected resources in approved scope to show which are exploitable.
“…we've been continuously validating … the efficacy of Cracken with our own pen tests, like external pen test findings. Just being sure that we could recreate those with Cracken. It's been going good so far…”
More integrations

Tenable
Cracken attacks Tenable findings in scope to prove which ones an attacker reaches.
Qualys
Cracken queries your Qualys detections live and launches a fresh scan when needed.

CrowdStrike Spotlight
Cracken proves which CrowdStrike Spotlight vulnerabilities are exploitable on those hosts.
Attack with real Amazon Inspector context.
See how Cracken works what Amazon Inspector already knows into attack paths it proves end to end.


