Cracken + GitHub
Cracken queries GitHub code scanning, secret scanning, and Dependabot alerts mid-operation. Every attack it attempts starts from your real code risk.
Connecting GitHub Advanced Security
- Connect with
A GitHub fine-grained personal access token scoped to the chosen organizations and repositories, with read access to Metadata, Issues, Pull requests, Code scanning alerts, Secret scanning alerts and Dependabot alerts. A classic token needs repo and security_events instead.
- Cadence
Queried live during an operation — a direct connector, not a scheduled sync.
- Requires
GitHub Advanced Security enabled for the security-alert data; access to every organization and repository Cracken should read. Organization policy may require an owner to approve the token first.
What Cracken gets from GitHub Advanced Security
Repositories with full_name, private, description, language, default_branch, open_issues_count, updated_at and html_url
Issues with number, title, state, labels[], author login and created_at
Pull requests with number, title, state, draft, author login, created_at and merged_at
Code scanning alerts with rule_id, rule_severity, rule_description, the tool name that raised them, state and url
Secret scanning alerts with secret_type, secret_type_display_name, validity, resolution and state
Dependabot alerts with package name, manifest_path, severity, ghsa_id, cve_id and the advisory summary
In the Cybergraph: a URL node for the repo, one Finding node per issue / PR / code-scanning / secret-scanning / Dependabot alert, and a cve: Vulnerability node hung off any Dependabot alert that carries a CVE
What GitHub Advanced Security does not do
Cracken's GitHub connection is read-only. It never opens an issue, comments, dismisses an alert or pushes code. Alerts are pulled one repository at a time and you name the repository each time; there is no organization-wide sweep, and nothing enters the Cybergraph until someone explicitly adds it.
How Cracken uses GitHub Advanced Security
- 01
Connect GitHub with an access token
- 02
Let Cracken query repositories mid-operation
- 03
Add the results worth keeping to the Knowledge Base
- 04
Confirm it connected
Frequently asked questions
Does Cracken change my GitHub repositories?
No; Cracken's GitHub connector is read-only — it opens no pull requests, pushes no commits, and changes no repository settings.
Does connecting GitHub copy my source code into Cracken?
No; the connector reads repository metadata and security alerts through the GitHub API without cloning repositories or copying source files.
“…we've been continuously validating … the efficacy of Cracken with our own pen tests, like external pen test findings. Just being sure that we could recreate those with Cracken. It's been going good so far…”
More integrations
Attack with real GitHub Advanced Security context.
See how Cracken works what GitHub Advanced Security already knows into attack paths it proves end to end.



