All integrations
Sherlock logo
// Tentacle Tool · OSINT

Cracken + Sherlock

Cracken runs Sherlock to check one handle against its maintained site list. It gets back a fast, found-only list of the profile URLs where it resolves — no status table, no profile-page parsing.

Get started
// 01

Connecting Sherlock

Connect with

No credentials — runs on your own Tentacle

Cadence

Runs on demand — installed per Tentacle, then invoked during an operation

Requires

Linux or macOS Tentacle

// 02

What Cracken gets from Sherlock

  • For one username, the list of sites where that handle exists

  • The profile URL for each hit across its maintained site list (400+ networks)

// 03

What Sherlock does not do

Checks only whether the username is present on a site. It does not read account contents or confirm that the matched accounts belong to the same person, and it does not version-check the installed binary.

// 04

How Cracken uses Sherlock

  1. 01

    Install Sherlock on a Tentacle

  2. 02

    Hand Cracken a username

  3. 03

    Read the hits and pivot

  4. 04

    Confirm the Tentacle is ready

// 05

Frequently asked questions

Does Sherlock log in to the accounts it finds?

No; Sherlock only requests public profile pages and submits no credentials, and Cracken never authenticates to those platforms.

What does Cracken do with the accounts Sherlock finds?

Cracken treats them as reconnaissance — names, employers, reused handles, and other public detail feed later stages of the same operation.

“I've been pretty impressed with how CrackenAGI is able to do its vulnerability discovery, enumeration, reconnaissance, as well as eventually being able to actually execute different exploitation paths.”

Cybersecurity Engineer, red team · test-and-measurement manufacturer

Attack with real Sherlock context.

See how Cracken runs Sherlock on a Tentacle you host, and proves what it finds end to end.