
Cracken + Orca Security
Orca's SideScanning builds its risk picture from block-storage snapshots without sending a packet at your workloads. Cracken sends the packets. It reports which of those findings an attacker actually reaches on the running system.
Connecting Orca Security
- Connect with
An Orca Security API token
- Cadence
Syncs on a schedule — every 6 hours by default
- Requires
The hosted connection service enabled on your deployment — always on for Cracken-hosted workspaces
What Cracken gets from Orca Security
Cloud security posture findings with severity (critical, high, medium, low, info) and state (open, resolved, snoozed)
The cloud resource each finding sits on — resource type plus resource id or name
cve list with cvss_base_score, cvss_vector and cvss_version where Orca carries them
device — hostnames, ipv4s and tags — which lands as a Device node linked to the Finding
first_seen, last_seen and state_updated_at
solution, patchable, category and vulnerability_url
vendor_id and vendor_severity, Orca's own labels kept beside the normalized ones
What Orca Security does not do
Read-only and one action wide: Cracken lists Orca Security findings and nothing else. It cannot start a scan, and it cannot resolve, snooze or comment on a finding. Self-hosted deployments cannot connect Orca unless the hosted connection service is enabled, a data-residency decision: credentials and synced findings leave your environment.
How Cracken uses Orca Security
- 01
Connect Orca Security
- 02
Sync cloud findings
- 03
Attack the live workload
- 04
Confirm it connected
Frequently asked questions
Does Cracken's Orca integration touch my running cloud workloads?
Reading findings does not: Orca Security collects them agentlessly from block-storage snapshots, and Cracken pulls results via an API token. Validation does, attacking only your approved scope from a Tentacle you control.
How often does Cracken sync Orca findings?
Cracken pulls Orca findings on a recurring cycle, about every six hours, and can also query Orca directly for current findings during an operation.
“I've been pretty impressed with how CrackenAGI is able to do its vulnerability discovery, enumeration, reconnaissance, as well as eventually being able to actually execute different exploitation paths.”
More integrations

Wiz
Cracken attacks Wiz findings in your cloud accounts to prove which reach impact.

Microsoft Defender for Cloud
Cracken proves which Microsoft Defender for Cloud recommendations an attacker can exploit.

CrowdStrike Falcon
Cracken shows what CrowdStrike Falcon caught and missed against real attacks.
Attack with real Orca Security context.
See how Cracken works what Orca Security already knows into attack paths it proves end to end.


