
Cracken + SentinelOne
Cracken runs live techniques against your Singularity-managed endpoints. It reads SentinelOne's alerts afterwards, separating what the agent flagged, what it blocked outright, and what it let run unnoticed.
Connecting SentinelOne
- Connect with
A SentinelOne API token and your management console base URL
- Cadence
Fetched on demand during an operation, not on a schedule — Cracken triggers a fresh pull when it needs current alerts.
- Requires
The hosted connection service enabled on your deployment — always on for Cracken-hosted workspaces
What Cracken gets from SentinelOne
EDR alerts with title, description, severity and status (new, in_progress, resolved, false_positive)
verdict, plus vendor_severity and vendor_status — SentinelOne's own labels beside the normalized ones
Process detail: process_filename, process_filepath, process_command_line, pid, parent_pid and process_sha1 / sha256 / md5
The identity on the alert: user_name, windows_sid, active_directory_user_id and active_directory_domain
device — hostnames and ipv4s of the endpoint the alert fired on
mitre — the MITRE entries carried on the alert
observables — the indicator objects carried on the alert
first_event_time, last_event_time and resolved_time
What SentinelOne does not do
SentinelOne is never synced on a schedule. Cracken pulls alerts on demand instead, and they do not land in the Cybergraph. Nothing is written back: Cracken cannot isolate a host, kill a process, or change an alert's status in the SentinelOne console.
How Cracken uses SentinelOne
- 01
Connect SentinelOne
- 02
Attack the endpoints
- 03
Sort flagged from blocked from missed
- 04
Confirm it connected
Frequently asked questions
Does Cracken change anything in the SentinelOne console?
No; Cracken reads SentinelOne alert data with a Singularity console API token and changes nothing — no policies, settings, exclusions, threat status, or response actions.
What happens if SentinelOne is in Protect mode and blocks Cracken?
A block is a result, not a failed test; Cracken records the blocked command with its SentinelOne alert and marks it prevented, not undetected.
“I've been pretty impressed with how CrackenAGI is able to do its vulnerability discovery, enumeration, reconnaissance, as well as eventually being able to actually execute different exploitation paths.”
More integrations

CrowdStrike Falcon
Cracken shows what CrowdStrike Falcon caught and missed against real attacks.

Microsoft Defender for Endpoint
Cracken attacks your devices, then names which techniques Microsoft Defender for Endpoint caught.

Tenable
Cracken attacks Tenable findings in scope to prove which ones an attacker reaches.
Attack with real SentinelOne context.
See how Cracken works what SentinelOne already knows into attack paths it proves end to end.

