
Cracken + Nikto
Cracken runs Nikto against a web server to flag dangerous files, outdated software versions, and misconfigurations. It works each hit live to see which one actually lets an attacker in.
Connecting Nikto
- Connect with
No credentials — runs on your own Tentacle
- Cadence
Runs on demand — installed on a Tentacle, then invoked during an operation (the agent can install and uninstall it mid-run)
- Requires
A Tentacle running Linux — macOS is not supported, so a macOS Tentacle reports Not eligible. Free licence, nothing to purchase and no credentials to supply.
What Cracken gets from Nikto
Findings against a web server, classified by Nikto's own tuning categories: interesting file / seen in logs, misconfiguration / default file, information disclosure, injection (XSS/script/HTML), remote file retrieval inside web root, denial of service, remote file retrieval server-wide, command execution / remote shell, SQL injection, file upload, authentication bypass, software identification, remote source inclusion, web service, administrative console
Identified web server and software, fingerprinted from headers, content and file analysis
Hits from checks for 8,000+ potentially dangerous files and programs
Outdated-version findings against thousands of servers and components
Reports written as json, xml, htm, txt, csv or sql, several formats per scan
What Nikto does not do
Nikto identifies and reports; its tuning list names the vulnerability classes it checks for, not attacks it carries out, and the manpage describes it as a scanner performing tests for items "generally considered dangerous" rather than an exploitation tool. Cracken's nikto edition is Linux-only, so it registers as "Not eligible" on a macOS Tentacle, and the vendor states Nikto "focuses on coverage and accuracy over speed" — it is not a fast or quiet scan.
How Cracken uses Nikto
- 01
Install Nikto on a Linux Tentacle
- 02
Point Cracken at a web server in scope
- 03
Work each finding against the live target
- 04
Confirm the Tentacle is ready
Frequently asked questions
Can Cracken run Nikto on macOS or Windows?
Nikto is cross-platform Perl, but Cracken packages it to run on Linux Tentacles, the Kali containers on infrastructure you control.
Is running Nikto against my server safe?
Nikto is loud in server and WAF logs but only probes for known-bad files rather than exploiting them. Cracken runs it against your scoped target from a Tentacle you control.
“…we've been continuously validating … the efficacy of Cracken with our own pen tests, like external pen test findings. Just being sure that we could recreate those with Cracken. It's been going good so far…”
Attack with real Nikto context.
See how Cracken runs Nikto on a Tentacle you host, and proves what it finds end to end.




