
Cracken + Shodan
Cracken writes Shodan dorks and host lookups mid-operation. It takes its next move from the banners, versions and CVEs that come back — without a packet reaching the target.
Connecting Shodan
- Connect with
A Shodan API key
- Cadence
Queried live during an operation
- Requires
No prerequisites
What Cracken gets from Shodan
IPAddress nodes carrying org, isp, asn, country_name, city, os and last_update
DNSName nodes for every hostname Shodan lists on the IP
Service nodes per open port with port, transport, product and version
Port nodes for search hits, which carry a single port and transport but no service list
Vulnerability nodes, one per CVE in Shodan's vulns list
Host lookup also returns domains, the full ports array, and a banner truncated to 200 characters per service
Search returns items with ip, port, transport, hostnames, org, country_name, os, timestamp and vulns, plus a result total
DNS resolve returns hostname to IP; DNS reverse returns IP to hostnames
What Shodan does not do
Shodan is passive and read-only — every action is a lookup, a search, a count or a DNS resolution; nothing is scanned and nothing is written. Its results also do not sync into the Cybergraph on their own: nodes appear only when someone explicitly pushes selected items to the knowledge base, and there is no scheduler that touches Shodan at all.
How Cracken uses Shodan
- 01
Connect Shodan with an API key
- 02
Look the target up in Shodan
- 03
Push the hosts that matter into the graph
- 04
Confirm it connected
Frequently asked questions
Does looking a target up in Shodan send traffic to that target?
No; Shodan runs its own internet-wide crawlers and Cracken reads their stored results, so the lookup reaches Shodan, never the target.
How current is the data Shodan returns?
As current as Shodan's last crawl — days or months behind reality — so Cracken stamps each imported host with the date Shodan last observed it.
“I've been pretty impressed with how CrackenAGI is able to do its vulnerability discovery, enumeration, reconnaissance, as well as eventually being able to actually execute different exploitation paths.”
More integrations

CrowdStrike Falcon
Cracken shows what CrowdStrike Falcon caught and missed against real attacks.

Tenable
Cracken attacks Tenable findings in scope to prove which ones an attacker reaches.
GitHub Advanced Security
Cracken queries your GitHub repositories and their scanning and Dependabot alerts live.
Attack with real Shodan context.
See how Cracken works what Shodan already knows into attack paths it proves end to end.


