All integrations
Orca Security logo
// Data Integration · Cloud Security

Cracken + Orca Security

Orca's SideScanning builds its risk picture from block-storage snapshots without sending a packet at your workloads. Cracken sends the packets. It reports which of those findings an attacker actually reaches on the running system.

Get started
// 01

Connecting Orca Security

Connect with

An Orca Security API token

Cadence

Syncs on a schedule — every 6 hours by default

Requires

The hosted connection service enabled on your deployment — always on for Cracken-hosted workspaces

// 02

What Cracken gets from Orca Security

  • Cloud security posture findings with severity (critical, high, medium, low, info) and state (open, resolved, snoozed)

  • The cloud resource each finding sits on — resource type plus resource id or name

  • cve list with cvss_base_score, cvss_vector and cvss_version where Orca carries them

  • device — hostnames, ipv4s and tags — which lands as a Device node linked to the Finding

  • first_seen, last_seen and state_updated_at

  • solution, patchable, category and vulnerability_url

  • vendor_id and vendor_severity, Orca's own labels kept beside the normalized ones

// 03

What Orca Security does not do

Read-only and one action wide: Cracken lists Orca Security findings and nothing else. It cannot start a scan, and it cannot resolve, snooze or comment on a finding. Self-hosted deployments cannot connect Orca unless the hosted connection service is enabled, a data-residency decision: credentials and synced findings leave your environment.

// 04

How Cracken uses Orca Security

  1. 01

    Connect Orca Security

  2. 02

    Sync cloud findings

  3. 03

    Attack the live workload

  4. 04

    Confirm it connected

// 05

Frequently asked questions

Does Cracken's Orca integration touch my running cloud workloads?

Reading findings does not: Orca Security collects them agentlessly from block-storage snapshots, and Cracken pulls results via an API token. Validation does, attacking only your approved scope from a Tentacle you control.

How often does Cracken sync Orca findings?

Cracken pulls Orca findings on a recurring cycle, about every six hours, and can also query Orca directly for current findings during an operation.

“I've been pretty impressed with how CrackenAGI is able to do its vulnerability discovery, enumeration, reconnaissance, as well as eventually being able to actually execute different exploitation paths.”

Cybersecurity Engineer, red team · test-and-measurement manufacturer

Attack with real Orca Security context.

See how Cracken works what Orca Security already knows into attack paths it proves end to end.