
Cracken + Microsoft Defender Vulnerability Management
Microsoft Defender Vulnerability Management ranks its security recommendations by how much each one would move your exposure score. Cracken ranks the same weaknesses by which ones it got through on your devices.
Connecting Microsoft Defender Vulnerability Management
- Connect with
No credential fields — an administrator signs in through a Microsoft authorization flow and grants tenant-wide consent to the requested WindowsDefenderATP application permissions.
- Cadence
Syncs on a schedule — every 6 hours by default — and can be re-synced on demand via the Trigger Scan action.
- Requires
Microsoft Defender Vulnerability Management enabled, and a Privileged Role Administrator, Cloud Application Administrator or Global Administrator to grant tenant-wide consent. Consent must be granted again if the application's requested permissions change.
What Cracken gets from Microsoft Defender Vulnerability Management
Vulnerability Findings with name, description, severity and state (new, active, re-opened, fixed)
cve[] identifiers with cvss_base_score, cvss_vector and cvss_version
The device{} the weakness sits on, carrying hostnames, ipv4s and tags[]
patchable plus a solution string, and first_seen / last_seen / state_updated_at
Defender's own grading alongside Cracken's: vendor, vendor_id, vendor_severity and vendor_scan_id
In the Cybergraph: a Device node CONTAINS a Finding node, which CONTAINS a cve: Vulnerability node
What Microsoft Defender Vulnerability Management does not do
It connects by OAuth only, so there is no client-secret form to fill in as there is for the other Microsoft connectors. Nothing is written back beyond a request to re-sync: Cracken cannot close a weakness, accept a risk, or change a security recommendation in Defender.
How Cracken uses Microsoft Defender Vulnerability Management
- 01
Authorize the Defender connection
- 02
Sync device findings
- 03
Prove exploitability
- 04
Confirm it connected
Frequently asked questions
Does Cracken install anything on my devices to validate Defender findings?
No; Defender Vulnerability Management already collects the findings from onboarded devices, and Cracken's attack traffic comes from a Tentacle you host, not your devices.
How is this different from Cracken's Microsoft Defender for Endpoint integration?
This integration syncs vulnerability findings Cracken validates by attacking the devices; the separate Defender for Endpoint integration supplies detection alerts pulled on demand.
“…we've been continuously validating … the efficacy of Cracken with our own pen tests, like external pen test findings. Just being sure that we could recreate those with Cracken. It's been going good so far…”
More integrations

Tenable
Cracken attacks Tenable findings in scope to prove which ones an attacker reaches.
Qualys
Cracken queries your Qualys detections live and launches a fresh scan when needed.
Amazon Inspector
Cracken proves which Amazon Inspector findings an attacker can actually reach.
Attack with real Microsoft Defender Vulnerability Management context.
See how Cracken works what Microsoft Defender Vulnerability Management already knows into attack paths it proves end to end.


