All integrations
h8mail logo
// Tentacle Tool · OSINT

Cracken + h8mail

Cracken runs h8mail to check an email against breach services and local dump files on the Tentacle. It chases the related addresses it turns up.

Get started
// 01

Connecting h8mail

Connect with

No credentials — runs on your own Tentacle

Cadence

Runs on demand — installed on a Tentacle, then invoked during an operation (the agent can install and uninstall it mid-run)

Requires

A Tentacle running Linux or macOS. Free licence, nothing to purchase and no credentials to supply.

// 02

What Cracken gets from h8mail

  • Number of breaches an email appears in (HaveIBeenPwned v3)

  • URLs of pastes and text files mentioning the target (HIBP Pastes)

  • Related emails — a count from Hunter.io public, cleartext addresses from the Hunter.io service — which h8mail can chase back into the ongoing search

  • Cleartext passwords, hashes and salts, usernames, IPs and domains (Snusbase, Leak-Lookup, Dehashed, IntelX, scylla.so, Breachdirectory)

  • Bitcoin wallets and IBANs (IntelX)

  • Last-seen-in-breaches and social media profiles (Emailrep.io)

  • Hits from local dump files searched offline — the "Breach Compilation" torrent and "Collection#1", cleartext or .gz

  • CSV or JSON output, with breach results regrouped per target and method

// 03

What h8mail does not do

h8mail ships no breach data of its own. Every source of cleartext passwords needs an API key, and Cracken supplies none, so a default run reaches only the free public sources and returns counts rather than credentials. Offline search needs breach dumps such as Breach Compilation or Collection#1 that you stage yourself.

// 04

How Cracken uses h8mail

  1. 01

    Install h8mail on a Tentacle

  2. 02

    Point Cracken at an address or a list of them

  3. 03

    Read the exposure, then chase it

  4. 04

    Confirm the Tentacle is ready

// 05

Frequently asked questions

Does h8mail need API keys to find breach data?

Not always; h8mail queries services like HaveIBeenPwned, Dehashed, Snusbase and IntelX when keys are set, but can also search local breach files without one.

What leaves the environment when Cracken runs h8mail?

Only h8mail's queries to whatever breach or reconnaissance APIs are configured; local dump-file searches run entirely offline on the Tentacle.

“I've been pretty impressed with how CrackenAGI is able to do its vulnerability discovery, enumeration, reconnaissance, as well as eventually being able to actually execute different exploitation paths.”

Cybersecurity Engineer, red team · test-and-measurement manufacturer

Attack with real h8mail context.

See how Cracken runs h8mail on a Tentacle you host, and proves what it finds end to end.