
Cracken + Nuclei
Cracken runs Nuclei's template checks against a host to catch known CVEs, exposed panels, and default credentials. It pushes on each hit from the same shell.
Connecting Nuclei
- Connect with
No credentials — runs on your own Tentacle
- Cadence
Runs on demand — installed per Tentacle, then invoked during an operation
- Requires
Linux or macOS Tentacle
What Cracken gets from Nuclei
Template matches, each carrying the template id and name
Severity (info/low/medium/high/critical)
The matched-at URL or host
Template tags and any CVE/CWE metadata the template declares
Matcher/extractor output for the hit
What Nuclei does not do
Template-driven: it only reports an issue a loaded YAML template matches — no template, no finding — and runs the template's check rather than a full exploit.
How Cracken uses Nuclei
- 01
Install Nuclei on a Tentacle
- 02
Point an operation at a host
- 03
Chase the hits
- 04
Confirm the Tentacle is ready
Frequently asked questions
Which Nuclei templates does Cracken use?
Cracken drives the standard Nuclei binary with ProjectDiscovery's community template collection, and its agent selects which templates and severity levels to run per target.
Is a Nuclei detection treated as a confirmed vulnerability?
No. A Nuclei detection is a lead; Cracken reads it and attempts to reproduce or exploit it, so a finding is what Cracken proved.
“…we've been continuously validating … the efficacy of Cracken with our own pen tests, like external pen test findings. Just being sure that we could recreate those with Cracken. It's been going good so far…”
Attack with real Nuclei context.
See how Cracken runs Nuclei on a Tentacle you host, and proves what it finds end to end.





