
Cracken + CrowdStrike Spotlight
CrowdStrike Falcon Spotlight rates every vulnerability by what ExPRT.AI predicts attackers are likely to exploit somewhere in the world. Cracken replaces that prediction with evidence from your own hosts, reporting the ones it exploited.
Connecting CrowdStrike Spotlight
- Connect with
The Falcon API Base URL for your cloud plus the Client ID and Client Secret of an API client granted Read on Vulnerabilities, Hosts and Host Groups, User Management, Prevention Policies, Device Control Policies, Response Policies and Sensor Update Policies.
- Cadence
Syncs on a schedule — every 6 hours by default — and can be re-synced on demand via the Trigger Scan action.
- Requires
CrowdStrike Exposure Management enabled, plus access to Falcon → API Clients and Keys with permission to create an API client.
What Cracken gets from CrowdStrike Spotlight
Vulnerability Findings with name, description, severity and state (new, active, re-opened, fixed)
cve[] identifiers with cvss_base_score, cvss_vector and cvss_version
The host the finding sits on as a device{} object with hostnames, ipv4s and tags[]
patchable and a solution string, plus first_seen, last_seen and state_updated_at
Spotlight's own grading kept beside Cracken's: vendor, vendor_id, vendor_severity and vendor_scan_id
In the Cybergraph: a Device node CONTAINS a Finding node, which CONTAINS a cve: Vulnerability node
What CrowdStrike Spotlight does not do
Nothing is written back to Falcon Spotlight beyond a request to re-sync. Cracken cannot close, remediate, suppress or re-rate a Spotlight vulnerability, and it never installs or runs a scanner of its own on those hosts.
How Cracken uses CrowdStrike Spotlight
- 01
Connect CrowdStrike Spotlight
- 02
Sync vulnerability findings
- 03
Prove which are exploitable
- 04
Confirm it connected
Frequently asked questions
How is the CrowdStrike Spotlight integration different from Cracken's CrowdStrike Falcon integration?
Spotlight supplies vulnerability findings Cracken syncs and validates by attacking hosts; the separate Falcon EDR integration supplies detection alerts pulled on demand, and connecting one does not connect the other.
Does Cracken change anything in CrowdStrike Falcon?
No; it reads findings through a Falcon API client you create and never alters Spotlight policies, suppresses findings, or writes to the Falcon console.
“…we've been continuously validating … the efficacy of Cracken with our own pen tests, like external pen test findings. Just being sure that we could recreate those with Cracken. It's been going good so far…”
More integrations

Tenable
Cracken attacks Tenable findings in scope to prove which ones an attacker reaches.
Qualys
Cracken queries your Qualys detections live and launches a fresh scan when needed.
Amazon Inspector
Cracken proves which Amazon Inspector findings an attacker can actually reach.
Attack with real CrowdStrike Spotlight context.
See how Cracken works what CrowdStrike Spotlight already knows into attack paths it proves end to end.


