Cracken + Recon-ng
Cracken installs Recon-ng modules from the marketplace, runs them against a domain. It reads the workspace they fill to choose the next module.
Connecting Recon-ng
- Connect with
No credentials — runs on your own Tentacle
- Cadence
Runs on demand — installed per Tentacle, then invoked during an operation
- Requires
Linux or macOS Tentacle
What Cracken gets from Recon-ng
Whatever marketplace modules write into the workspace tables — hosts, contacts, credentials, domains, netblocks, ports and vulnerabilities among them
A per-domain workspace the modules populate
What Recon-ng does not do
Ships no data on its own: what it yields depends entirely on which marketplace modules are installed and run against the workspace. Cracken does not version-check the installed binary.
How Cracken uses Recon-ng
- 01
Install Recon-ng on a Tentacle
- 02
Open a workspace and load modules
- 03
Run the modules and read the workspace
- 04
Confirm the Tentacle is ready
Frequently asked questions
Do Recon-ng modules need API keys?
Many Recon-ng modules need no key; those backed by commercial data providers need one added to Recon-ng's key store.
Where is the data Recon-ng collects stored?
Recon-ng writes to a SQLite workspace database on the Tentacle — a Kali container on infrastructure you control — which Cracken reads from a shell.
“I've been pretty impressed with how CrackenAGI is able to do its vulnerability discovery, enumeration, reconnaissance, as well as eventually being able to actually execute different exploitation paths.”
Attack with real Recon-ng context.
See how Cracken runs Recon-ng on a Tentacle you host, and proves what it finds end to end.




