
Cracken + CrowdStrike
Cracken runs real techniques on the hosts your Falcon sensors cover. It reads CrowdStrike Falcon's alerts for that window. You see which techniques Falcon raised, at what severity, and which it never saw.
Connecting CrowdStrike Falcon
- Connect with
The Falcon API Base URL for your CrowdStrike cloud (US-1, US-2, EU-1 or US-GOV-1) plus the Client ID and Client Secret of an API client granted Read on Alerts, Hosts and Host Groups, User Management, Prevention Policies, Device Control Policies, Response Policies and Sensor Update Policies.
- Cadence
Fetched on demand during an operation, not on a schedule — Cracken triggers a fresh pull when it needs current alerts.
- Requires
Access to CrowdStrike Falcon → API Clients and Keys, with permission to create an API client. The client secret is shown only once.
What Cracken gets from CrowdStrike Falcon
EDR Alerts with title, description, severity, status and Falcon's own verdict
The process that triggered the alert: process_filename, process_filepath, process_command_line, pid, parent_pid and process_sha256 / sha1 / md5
The identity on the alert: user_name, windows_sid, active_directory_user_id and active_directory_domain
first_event_time, last_event_time and resolved_time, with assigned_user
A device{} object carrying hostnames and ipv4s
A mitre[] array and an observables[] array on each alert, plus vendor_severity, vendor_status and the raw vendor_data{}
What CrowdStrike Falcon does not do
CrowdStrike Falcon is never synced on a schedule. Cracken pulls alerts on demand instead, and they do not land in the Cybergraph. Nothing is written back to Falcon: Cracken cannot contain or isolate a host, kill a process, or change an alert's status.
How Cracken uses CrowdStrike Falcon
- 01
Create a read-only Falcon API client
- 02
Run the attack operation
- 03
Match alerts to techniques
- 04
Confirm it connected
Frequently asked questions
What CrowdStrike Falcon API scopes does Cracken need?
A Falcon API client with Read, never write, on seven scopes: Alerts, Hosts and Host Groups, User Management, Prevention Policies, Device Control Policies, Response Policies, and Sensor Update Policies, plus the client ID, secret, and your Falcon cloud's API base URL.
Does Cracken run its attacks through Falcon Real Time Response?
No; Cracken runs techniques from a Tentacle you control rather than Falcon Real Time Response, then only reads Falcon alerts for the tested hosts and window.
“I've been pretty impressed with how CrackenAGI is able to do its vulnerability discovery, enumeration, reconnaissance, as well as eventually being able to actually execute different exploitation paths.”
More integrations

Microsoft Defender for Endpoint
Cracken attacks your devices, then names which techniques Microsoft Defender for Endpoint caught.

SentinelOne
Cracken attacks your endpoints, then reads what SentinelOne flagged, blocked, and missed.

Tenable
Cracken attacks Tenable findings in scope to prove which ones an attacker reaches.
Attack with real CrowdStrike Falcon context.
See how Cracken works what CrowdStrike Falcon already knows into attack paths it proves end to end.

