Cracken + Covenant
Once it ships, Cracken will drive Covenant's in-memory .NET Grunt implants over HTTP and HTTPS listeners, and SMB named pipes to pivot to hosts with no egress, as stages of a validated intrusion. Each will be gated by your approval policy.
Connecting Covenant
- Connect with
No credentials — runs on your own Tentacle
- Cadence
Not running yet
- Requires
The C2 Tools entitlement, which only unlocks the (empty) C2 tab in the Integration Center — no connector ships yet
What Cracken gets from Covenant
Cracken reads nothing from Covenant until its connector ships.
What Covenant does not do
Nothing yet — Covenant is listed as Coming soon in the Integration Center and its card reads "Not available yet", with no way to configure it. No connector exists, so Grunts, listeners and their task results are not imported into the Knowledge base or the Cybergraph.
How Cracken uses Covenant
- 01
Connect Covenant
- 02
Stage the intrusion
- 03
Run under approval gates
Frequently asked questions
Is the Covenant integration self-hosted?
Yes; when it ships, Cracken will connect to your self-hosted Covenant server and task its Grunt implants, leaving the server and listeners under your control.
Does Cracken change my Covenant setup?
No; Cracken will drive your existing Covenant server as-is, sequencing Grunt tasks under approval gates without altering your listeners, profiles, or configuration.
More integrations

Brute Ratel
When it ships, Cracken will drive Brute Ratel's Badger implants across an operation.
Cobalt Strike
When it ships, Cracken will drive Cobalt Strike's Beacon from your team server.

Empire
When it ships, Cracken will drive Empire's modules as approval-gated stages.

