Cracken + Okta
Cracken lists your Okta users and groups, active and inactive alike. It attacks those identities to prove which account-takeover and privilege-escalation paths actually work.
Connecting Okta
- Connect with
An Okta API token and your Okta domain
- Cadence
Syncs on a schedule — every 6 hours by default
- Requires
The hosted connection service enabled on your deployment — always on for Cracken-hosted workspaces
What Cracken gets from Okta
Users, filterable by status (active, inactive, all) and free-text search
Groups, filterable by free-text search
What Okta does not do
Nothing is written back: the hosted connection is read-only, so Cracken cannot create, disable or reset an Okta user, or change a group. Okta records never become Cybergraph nodes either — users and groups are listed, not mapped into the graph.
How Cracken uses Okta
- 01
Connect Okta
- 02
List users and groups
- 03
Attack the identities
- 04
Confirm it connected
Frequently asked questions
What does Cracken read from Okta?
Users and groups. Cracken calls the Okta API with the org domain and token you supply, builds the identity map, and writes nothing back to Okta.
How do I revoke the Okta API token Cracken uses?
Revoke it in Okta by deactivating the admin who created it — the token inherits that admin's privileges and is deprovisioned with that account.
“I've been pretty impressed with how CrackenAGI is able to do its vulnerability discovery, enumeration, reconnaissance, as well as eventually being able to actually execute different exploitation paths.”
More integrations

Microsoft Entra ID
Cracken attacks Microsoft Entra ID identities to prove which reach Global Administrator.

CrowdStrike Falcon
Cracken shows what CrowdStrike Falcon caught and missed against real attacks.

Tenable
Cracken attacks Tenable findings in scope to prove which ones an attacker reaches.
Attack with real Okta context.
See how Cracken works what Okta already knows into attack paths it proves end to end.

