All integrations
// Tentacle Tool · OSINT

Cracken + Holehe

Cracken runs Holehe to push one email address through the password-reset, sign-up, and login flows of the sites it supports. It maps where that address has an account.

Get started
// 01

Connecting Holehe

Connect with

No credentials — runs on your own Tentacle

Cadence

Runs on demand — installed on a Tentacle, then invoked during an operation (the agent can install and uninstall it mid-run)

Requires

A Tentacle running Linux or macOS. Free licence, nothing to purchase and no credentials to supply.

// 02

What Cracken gets from Holehe

  • name — the service checked

  • domain — the site's domain

  • exists — whether an account is registered for that email

  • emailrecovery — a partially obfuscated recovery email, when the site returns one

  • phoneNumber — a partially obfuscated recovery phone number, when the site returns one

  • rateLimit — whether that check was rate-limited

  • others — any extra info the module surfaced

  • The method each module used: register, password recovery, or login

// 03

What Holehe does not do

Holehe tells you an account exists and returns whatever the forgotten-password flow leaks — nothing more. Recovery emails and phone numbers come back partially obfuscated (ex****e@gmail.com, 0*******78), and it retrieves no credentials or account contents. Its README states explicitly that it does not alert the target email; its only answer to a rate limit is to change IP.

// 04

How Cracken uses Holehe

  1. 01

    Install Holehe on a Tentacle

  2. 02

    Run Holehe against the address

  3. 03

    Read which services already know the address

  4. 04

    Confirm the Tentacle is ready

// 05

Frequently asked questions

Does Holehe alert the person whose email address is checked?

Holehe reads how a site's password-reset, sign-up, or login flow responds without completing it, by design. Since each site controls what it sends, that is intent, not a guarantee.

Does Holehe need API keys or accounts on the sites it checks?

No; Holehe works against the public password-reset, sign-up, and login endpoints of the services it supports with no keys or accounts required.

“I've been pretty impressed with how CrackenAGI is able to do its vulnerability discovery, enumeration, reconnaissance, as well as eventually being able to actually execute different exploitation paths.”

Cybersecurity Engineer, red team · test-and-measurement manufacturer

Attack with real Holehe context.

See how Cracken runs Holehe on a Tentacle you host, and proves what it finds end to end.