All integrations
CrowdStrike Falcon logo
// Data Integration · Endpoint Detection & Response

Cracken + CrowdStrike

Cracken runs real techniques on the hosts your Falcon sensors cover. It reads CrowdStrike Falcon's alerts for that window. You see which techniques Falcon raised, at what severity, and which it never saw.

Get started
// 01

Connecting CrowdStrike Falcon

Connect with

The Falcon API Base URL for your CrowdStrike cloud (US-1, US-2, EU-1 or US-GOV-1) plus the Client ID and Client Secret of an API client granted Read on Alerts, Hosts and Host Groups, User Management, Prevention Policies, Device Control Policies, Response Policies and Sensor Update Policies.

Cadence

Fetched on demand during an operation, not on a schedule — Cracken triggers a fresh pull when it needs current alerts.

Requires

Access to CrowdStrike Falcon → API Clients and Keys, with permission to create an API client. The client secret is shown only once.

// 02

What Cracken gets from CrowdStrike Falcon

  • EDR Alerts with title, description, severity, status and Falcon's own verdict

  • The process that triggered the alert: process_filename, process_filepath, process_command_line, pid, parent_pid and process_sha256 / sha1 / md5

  • The identity on the alert: user_name, windows_sid, active_directory_user_id and active_directory_domain

  • first_event_time, last_event_time and resolved_time, with assigned_user

  • A device{} object carrying hostnames and ipv4s

  • A mitre[] array and an observables[] array on each alert, plus vendor_severity, vendor_status and the raw vendor_data{}

// 03

What CrowdStrike Falcon does not do

CrowdStrike Falcon is never synced on a schedule. Cracken pulls alerts on demand instead, and they do not land in the Cybergraph. Nothing is written back to Falcon: Cracken cannot contain or isolate a host, kill a process, or change an alert's status.

// 04

How Cracken uses CrowdStrike Falcon

  1. 01

    Create a read-only Falcon API client

  2. 02

    Run the attack operation

  3. 03

    Match alerts to techniques

  4. 04

    Confirm it connected

// 05

Frequently asked questions

What CrowdStrike Falcon API scopes does Cracken need?

A Falcon API client with Read, never write, on seven scopes: Alerts, Hosts and Host Groups, User Management, Prevention Policies, Device Control Policies, Response Policies, and Sensor Update Policies, plus the client ID, secret, and your Falcon cloud's API base URL.

Does Cracken run its attacks through Falcon Real Time Response?

No; Cracken runs techniques from a Tentacle you control rather than Falcon Real Time Response, then only reads Falcon alerts for the tested hosts and window.

“I've been pretty impressed with how CrackenAGI is able to do its vulnerability discovery, enumeration, reconnaissance, as well as eventually being able to actually execute different exploitation paths.”

Cybersecurity Engineer, red team · test-and-measurement manufacturer

Attack with real CrowdStrike Falcon context.

See how Cracken works what CrowdStrike Falcon already knows into attack paths it proves end to end.