
Cracken + Tenable
The same CVE carries the same Tenable VPR for every customer that has it. Cracken attacks those findings inside your environment. It proves which ones your own network and controls leave reachable.
Connecting Tenable
- Connect with
A Tenable client (access) key and secret key
- Cadence
Syncs on a schedule — every 6 hours by default, and the agent can force a fresh sync mid-operation
- Requires
The hosted connection service enabled on your deployment — always on for Cracken-hosted workspaces
What Cracken gets from Tenable
Vulnerability findings with severity (critical, high, medium, low, info) and state (new, active, re-opened, fixed)
cve list with cvss_base_score, cvss_vector, cvss_version and cvss_temporal_score
port, protocol and service on the affected asset
device — hostnames, ipv4s, tags — landed as a Device node linked to the Finding, and resource with its type and id/name
first_seen, last_seen, updated_at and state_updated_at
solution, patchable, category and vulnerability_url
vendor_severity, vendor_id and vendor_scan_id — Tenable's own rating and scan identifier kept beside the normalized severity
What Tenable does not do
Trigger Scan does not launch a Tenable scan — it posts an on-demand sync job to the hosted connection service to re-pull findings, and accepts nothing but optional tags. Nothing is written back to Tenable: no finding can be accepted, recast or closed from Cracken, because the client exposes read endpoints only. Self-hosted deployments cannot connect it without the hosted connection service enabled.
How Cracken uses Tenable
- 01
Connect Tenable
- 02
Sync the vulnerability findings
- 03
Prove what is reachable
- 04
Confirm it connected
Frequently asked questions
Does connecting Tenable change anything in my Tenable account?
No: Cracken only reads Tenable's findings and assets; the refresh it triggers re-pulls that, without starting scans, editing policies, closing findings, or writing back.
How often does Cracken refresh Tenable data?
Cracken re-pulls Tenable findings roughly every six hours, and an operation can also query Tenable directly mid-run for newer data.
“…we've been continuously validating … the efficacy of Cracken with our own pen tests, like external pen test findings. Just being sure that we could recreate those with Cracken. It's been going good so far…”
More integrations
Qualys
Cracken queries your Qualys detections live and launches a fresh scan when needed.
Amazon Inspector
Cracken proves which Amazon Inspector findings an attacker can actually reach.

CrowdStrike Spotlight
Cracken proves which CrowdStrike Spotlight vulnerabilities are exploitable on those hosts.
Attack with real Tenable context.
See how Cracken works what Tenable already knows into attack paths it proves end to end.


