
Cracken + Sliver
Once it ships, Cracken will drive Sliver's beacon and session implants as stages of a validated intrusion. Every action will stay under the same approval gates.
Connecting Sliver
- Connect with
No credentials — runs on your own Tentacle
- Cadence
Not running yet
- Requires
The C2 Tools entitlement, which only unlocks the (empty) C2 tab in the Integration Center — no connector ships yet
What Cracken gets from Sliver
Cracken reads nothing from Sliver until its connector ships.
What Sliver does not do
Nothing yet as an integration: the Sliver card is Coming soon and reads "Not available yet", with no server address or operator-config field to fill in. The Sliver in the repo today is Cracken's own cyberrange attacker infrastructure — a docker-compose Sliver server used by the demo ranges — not a connection to the Sliver server you operate, and no implant, session or beacon record is imported.
How Cracken uses Sliver
- 01
Establish a foothold
- 02
Stage Sliver implants under approval
- 03
Prove impact end to end
Frequently asked questions
How does Cracken use Sliver?
Cracken will drive Sliver's beacon and session implants across Windows, Linux, and macOS, over mTLS, WireGuard, HTTP(S), or DNS, as stages of one intrusion.
Does Cracken run Sliver without approval?
No; every Sliver task Cracken issues will run under the approval gates and autonomy limits you set.
More integrations

Brute Ratel
When it ships, Cracken will drive Brute Ratel's Badger implants across an operation.
Cobalt Strike
When it ships, Cracken will drive Cobalt Strike's Beacon from your team server.
Covenant
When it ships, Cracken will drive Covenant's in-memory Grunts across an operation.

