Cracken + Cobalt Strike
Once it ships, Cracken will drive Cobalt Strike's Beacon payload from the team server you already run, linking SMB and TCP beacons into staged pivots. Each will wait on an approval gate.
Connecting Cobalt Strike
- Connect with
No credentials — runs on your own Tentacle
- Cadence
Not running yet
- Requires
The C2 Tools entitlement, which only unlocks the (empty) C2 tab in the Integration Center — no connector ships yet
What Cracken gets from Cobalt Strike
Cracken reads nothing from Cobalt Strike until its connector ships.
What Cobalt Strike does not do
Nothing yet — the Cobalt Strike card is a Coming soon placeholder that reads "Not available yet" and has no Install or Configure control. Cracken has no team server connector, so no Beacon, listener, Malleable C2 profile or task output is read from a server you run.
How Cracken uses Cobalt Strike
- 01
Connect your team server
- 02
Stage the intrusion
- 03
Run under approval gates
Frequently asked questions
Does Cracken replace my Cobalt Strike team server?
No; when it ships, Cracken will drive Beacon through your existing Cobalt Strike team server's listeners and Malleable C2 profile, leaving licence and infrastructure yours.
How much control do I keep over what Cobalt Strike does?
Every Cobalt Strike Beacon task will sit behind an approval gate; intrusive actions, including linking a new SMB or TCP beacon, wait for explicit approval.
More integrations

Brute Ratel
When it ships, Cracken will drive Brute Ratel's Badger implants across an operation.
Covenant
When it ships, Cracken will drive Covenant's in-memory Grunts across an operation.

Empire
When it ships, Cracken will drive Empire's modules as approval-gated stages.

