Cracken + Subfinder
Cracken installs Tentacle tools on a Kali container you own and drives them from a shell. When Subfinder ships in that catalog, Cracken will point it at a root domain. It will take the hostnames off its raw output and probe them in the same operation. No query will reach the target.
Connecting Subfinder
- Connect with
No credentials — runs on your own Tentacle
- Cadence
Runs on demand once available — installed per Tentacle, then invoked during an operation
- Requires
Not yet installable — the definition is flagged coming soon, and the catalog blocks installing such tools; Linux or macOS Tentacle when it ships
What Cracken gets from Subfinder
Cracken reads nothing from Subfinder until its connector ships.
What Subfinder does not do
Catalogued but not yet available — it carries a Coming soon badge and cannot be installed; by design it is passive only (certificate-transparency logs and passive DNS), so it never actively resolves or contacts the target.
How Cracken uses Subfinder
- 01
Install Subfinder on your Tentacles
- 02
Name the root domain
- 03
Hand the hostnames to the next command
Frequently asked questions
Does Subfinder send traffic to the domain being enumerated?
No — Subfinder passively queries public sources such as certificate transparency logs and DNS datasets, so the domain's own servers log nothing.
Can I install Subfinder on a Tentacle today?
Not yet — Subfinder shows a Coming soon badge, but Amass, httpx, and Katana cover the same attack-surface recon on a Kali Linux Tentacle.


