All integrations
Nuclei logo
// Tentacle Tool · Vulnerability Scanning

Cracken + Nuclei

Cracken runs Nuclei's template checks against a host to catch known CVEs, exposed panels, and default credentials. It pushes on each hit from the same shell.

Get started
// 01

Connecting Nuclei

Connect with

No credentials — runs on your own Tentacle

Cadence

Runs on demand — installed per Tentacle, then invoked during an operation

Requires

Linux or macOS Tentacle

// 02

What Cracken gets from Nuclei

  • Template matches, each carrying the template id and name

  • Severity (info/low/medium/high/critical)

  • The matched-at URL or host

  • Template tags and any CVE/CWE metadata the template declares

  • Matcher/extractor output for the hit

// 03

What Nuclei does not do

Template-driven: it only reports an issue a loaded YAML template matches — no template, no finding — and runs the template's check rather than a full exploit.

// 04

How Cracken uses Nuclei

  1. 01

    Install Nuclei on a Tentacle

  2. 02

    Point an operation at a host

  3. 03

    Chase the hits

  4. 04

    Confirm the Tentacle is ready

// 05

Frequently asked questions

Which Nuclei templates does Cracken use?

Cracken drives the standard Nuclei binary with ProjectDiscovery's community template collection, and its agent selects which templates and severity levels to run per target.

Is a Nuclei detection treated as a confirmed vulnerability?

No. A Nuclei detection is a lead; Cracken reads it and attempts to reproduce or exploit it, so a finding is what Cracken proved.

“…we've been continuously validating … the efficacy of Cracken with our own pen tests, like external pen test findings. Just being sure that we could recreate those with Cracken. It's been going good so far…”

Cybersecurity Engineer · test-and-measurement manufacturer

Attack with real Nuclei context.

See how Cracken runs Nuclei on a Tentacle you host, and proves what it finds end to end.