Cracken + PhoneInfoga
Cracken runs PhoneInfoga to parse a number down to its country and formats. It works the dork set it builds across social networks, disposable-number services, and scam-report sites.
Connecting PhoneInfoga
- Connect with
No credentials — runs on your own Tentacle
- Cadence
Runs on demand — installed per Tentacle, then invoked during an operation
- Requires
Linux or macOS Tentacle
What Cracken gets from PhoneInfoga
A phone number broken into its country and international/local/E.164 formats
Carrier and line-type guess
Generated OSINT footprint queries — social, reputation/scam-report, and disposable-number lookups
What PhoneInfoga does not do
Passive footprinting only — it derives formats and lookup leads from open data and does not call or verify ownership of the number. Cracken does not version-check the installed binary.
How Cracken uses PhoneInfoga
- 01
Install PhoneInfoga on a Tentacle
- 02
Give Cracken a number in scope
- 03
Cracken runs the lookup and reads the output
- 04
Confirm the Tentacle is ready
Frequently asked questions
Does PhoneInfoga call or text the numbers Cracken looks up?
No — PhoneInfoga never contacts the number. It parses offline for the country and formats, queries OVH's public numbering API where covered, and writes Google search queries without running them.
Where does PhoneInfoga run when Cracken uses it?
PhoneInfoga runs on a Tentacle, a Kali Linux container on Linux or macOS infrastructure your team controls, not in a hosted cloud.
“I've been pretty impressed with how CrackenAGI is able to do its vulnerability discovery, enumeration, reconnaissance, as well as eventually being able to actually execute different exploitation paths.”
Attack with real PhoneInfoga context.
See how Cracken runs PhoneInfoga on a Tentacle you host, and proves what it finds end to end.




