Cracken + Holehe
Cracken runs Holehe to push one email address through the password-reset, sign-up, and login flows of the sites it supports. It maps where that address has an account.
Connecting Holehe
- Connect with
No credentials — runs on your own Tentacle
- Cadence
Runs on demand — installed on a Tentacle, then invoked during an operation (the agent can install and uninstall it mid-run)
- Requires
A Tentacle running Linux or macOS. Free licence, nothing to purchase and no credentials to supply.
What Cracken gets from Holehe
name — the service checked
domain — the site's domain
exists — whether an account is registered for that email
emailrecovery — a partially obfuscated recovery email, when the site returns one
phoneNumber — a partially obfuscated recovery phone number, when the site returns one
rateLimit — whether that check was rate-limited
others — any extra info the module surfaced
The method each module used: register, password recovery, or login
What Holehe does not do
Holehe tells you an account exists and returns whatever the forgotten-password flow leaks — nothing more. Recovery emails and phone numbers come back partially obfuscated (ex****e@gmail.com, 0*******78), and it retrieves no credentials or account contents. Its README states explicitly that it does not alert the target email; its only answer to a rate limit is to change IP.
How Cracken uses Holehe
- 01
Install Holehe on a Tentacle
- 02
Run Holehe against the address
- 03
Read which services already know the address
- 04
Confirm the Tentacle is ready
Frequently asked questions
Does Holehe alert the person whose email address is checked?
Holehe reads how a site's password-reset, sign-up, or login flow responds without completing it, by design. Since each site controls what it sends, that is intent, not a guarantee.
Does Holehe need API keys or accounts on the sites it checks?
No; Holehe works against the public password-reset, sign-up, and login endpoints of the services it supports with no keys or accounts required.
“I've been pretty impressed with how CrackenAGI is able to do its vulnerability discovery, enumeration, reconnaissance, as well as eventually being able to actually execute different exploitation paths.”
Attack with real Holehe context.
See how Cracken runs Holehe on a Tentacle you host, and proves what it finds end to end.




