
Cracken + Brute Ratel
Once it ships, Cracken will drive Brute Ratel's Badger implants as stages of a validated intrusion. Each will reach out over DNS-over-HTTPS and pivot inside over SMB or TCP, held at an approval gate.
Connecting Brute Ratel
- Connect with
No credentials — runs on your own Tentacle
- Cadence
Not running yet
- Requires
The C2 Tools entitlement, which only unlocks the (empty) C2 tab in the Integration Center — no connector ships yet
What Cracken gets from Brute Ratel
Cracken reads nothing from Brute Ratel until its connector ships.
What Brute Ratel does not do
Nothing yet — Brute Ratel is catalogued, not connectable: its Integration Center card carries a Coming soon badge and reads "Not available yet", with no Install or Configure control. There is no connector, no actions and no credential form anywhere in the backend, so nothing syncs and no Badger session, task or callback reaches Cracken.
How Cracken uses Brute Ratel
- 01
Establish a foothold
- 02
Stage Badgers under approval
- 03
Prove impact end to end
Frequently asked questions
Do we need our own Brute Ratel licence to use it with Cracken?
Yes; because Brute Ratel C4 is licensed one user per licence, Cracken will stage Badgers through your own installation, never reselling or bundling it.
Does Cracken run Brute Ratel Badgers without approval?
No; each Brute Ratel Badger action will be proposed as a step and run only after it clears your approval and scope limits.
More integrations
Cobalt Strike
When it ships, Cracken will drive Cobalt Strike's Beacon from your team server.
Covenant
When it ships, Cracken will drive Covenant's in-memory Grunts across an operation.

Empire
When it ships, Cracken will drive Empire's modules as approval-gated stages.

