
Cracken + SentinelOne VM
SentinelOne Vulnerability Management reads CVEs from inside the endpoint, off the application inventory its Singularity agent keeps. Cracken comes at those endpoints across the network. It proves which of the flaws an attacker can reach.
Connecting SentinelOne VM
- Connect with
A SentinelOne API token and your management console base URL
- Cadence
Syncs on a schedule — every 6 hours by default, and the agent can force a fresh sync mid-operation
- Requires
The hosted connection service enabled on your deployment — always on for Cracken-hosted workspaces
What Cracken gets from SentinelOne VM
Vulnerability findings with severity (critical, high, medium, low, info) and state (new, active, re-opened, fixed)
cve list with cvss_base_score, cvss_vector and cvss_version
device — hostnames, ipv4s, tags — of the endpoint carrying the finding, landed as a Device node linked to the Finding
port, protocol and service where SentinelOne supplies them
first_seen, last_seen, updated_at and state_updated_at
solution, patchable, category and vulnerability_url
vendor_id, vendor_severity and vendor_scan_id
What SentinelOne VM does not do
Trigger Scan does not start a SentinelOne scan — it posts an on-demand sync job to the hosted connection service to re-pull findings, and takes nothing but optional tags. There is no write path back into SentinelOne, and unlike the SentinelOne EDR integration this one is not filterable by host or user: its only filters are severity, state, CVE, resource ID and resource type.
How Cracken uses SentinelOne VM
- 01
Connect SentinelOne VM
- 02
Sync the endpoint findings
- 03
Attack the endpoints in scope
- 04
Confirm it connected
Frequently asked questions
Does Cracken need to install anything on my endpoints?
No; Cracken reads SentinelOne Vulnerability Management findings over the SentinelOne API with your console URL and token, adding no agent of its own.
Is SentinelOne VM the same as connecting SentinelOne for endpoint detection?
No; SentinelOne VM supplies vulnerability findings Cracken syncs and tries to exploit, while the separate endpoint detection integration supplies alerts Cracken reads on demand.
“…we've been continuously validating … the efficacy of Cracken with our own pen tests, like external pen test findings. Just being sure that we could recreate those with Cracken. It's been going good so far…”
More integrations

Tenable
Cracken attacks Tenable findings in scope to prove which ones an attacker reaches.
Qualys
Cracken queries your Qualys detections live and launches a fresh scan when needed.
Amazon Inspector
Cracken proves which Amazon Inspector findings an attacker can actually reach.
Attack with real SentinelOne VM context.
See how Cracken works what SentinelOne VM already knows into attack paths it proves end to end.


