
Cracken + Microsoft Defender for Cloud
Microsoft Defender for Cloud orders your subscriptions' security recommendations by how much each fix would raise your secure score. Cracken reorders that same list by which misconfiguration an attacker gets through first.
Connecting Microsoft Defender for Cloud
- Connect with
Directory Tenant ID, application Client ID and client-secret value for a single-tenant Entra app registration whose service principal holds the Azure Security Reader role on every subscription Cracken should read.
- Cadence
Syncs on a schedule — every 6 hours by default for a hosted connection.
- Requires
Microsoft Defender for Cloud enabled on the target subscriptions; permission to create an app registration and client secret, and to assign Azure roles on those subscriptions.
What Cracken gets from Microsoft Defender for Cloud
CSPM Findings (the Data tab's own label) with name, description, severity and state (open, resolved, snoozed)
The cloud resource each finding sits on as a resource{} object, filterable by resource_type and resource_id
category and a solution string describing the remediation Defender recommends
first_seen, last_seen and state_updated_at
Defender's own grading kept beside Cracken's: vendor, vendor_id and vendor_severity
In the Cybergraph: a Finding node per posture finding, joined to a Device node when the finding carries an asset
What Microsoft Defender for Cloud does not do
Cracken only reads findings: it cannot start a scan and has no write path, so it never resolves, snoozes or exempts a Defender for Cloud recommendation. Secure Score is not something Cracken reads — it sees severity and state per finding, not a subscription-level score.
How Cracken uses Microsoft Defender for Cloud
- 01
Connect Microsoft Defender for Cloud
- 02
Sync posture findings
- 03
Attack the cloud resources
- 04
Confirm it connected
Frequently asked questions
What does Cracken read from Microsoft Defender for Cloud?
Using the Microsoft Entra tenant ID, client ID, and client secret you register, Cracken reads Defender for Cloud's posture findings and writes nothing back.
Do I still need Defender for Cloud if Cracken validates the findings?
Yes; Defender for Cloud produces the posture findings and secure score, while Cracken proves which ones an attacker can exploit.
“I've been pretty impressed with how CrackenAGI is able to do its vulnerability discovery, enumeration, reconnaissance, as well as eventually being able to actually execute different exploitation paths.”
More integrations

Wiz
Cracken attacks Wiz findings in your cloud accounts to prove which reach impact.

Orca Security
Cracken proves which Orca Security findings an attacker can reach on the running workload.

CrowdStrike Falcon
Cracken shows what CrowdStrike Falcon caught and missed against real attacks.
Attack with real Microsoft Defender for Cloud context.
See how Cracken works what Microsoft Defender for Cloud already knows into attack paths it proves end to end.


