All integrations
Trivy logo
// Tentacle Tool · Container Security

Cracken + Trivy

Cracken runs Trivy inside a container image or filesystem to find the vulnerable packages and embedded secrets actually shipped. It works the ones it can reach from its foothold.

Get started
// 01

Connecting Trivy

Connect with

No credentials — runs on your own Tentacle

Cadence

Runs on demand — installed per Tentacle, then invoked during an operation

Requires

Linux or macOS Tentacle

// 02

What Cracken gets from Trivy

  • Vulnerable packages with package name, installed vs fixed version, CVE id and severity

  • Exposed secrets found in the image or filesystem

  • IaC/config misconfigurations

  • An SBOM of the scanned target

// 03

What Trivy does not do

Reports what is present in the image or filesystem — it does not prove a listed vulnerability is reachable or exploitable, which Cracken works separately.

// 04

How Cracken uses Trivy

  1. 01

    Install Trivy on a Tentacle

  2. 02

    Point Cracken at an image, filesystem, or repository

  3. 03

    Work the reachable entries

  4. 04

    Confirm the Tentacle is ready

// 05

Frequently asked questions

What can Cracken scan with Trivy?

Trivy scans container images, filesystems, and repositories for vulnerabilities in OS packages and dependencies, infrastructure-as-code misconfigurations, and leaked secrets, whichever an operation reaches.

Does a Trivy CVE become a Cracken finding?

Not on its own: Cracken treats each installed version as a lead, attempts to reach and use it, and records only what it demonstrated.

“…we've been continuously validating … the efficacy of Cracken with our own pen tests, like external pen test findings. Just being sure that we could recreate those with Cracken. It's been going good so far…”

Cybersecurity Engineer · test-and-measurement manufacturer

Attack with real Trivy context.

See how Cracken runs Trivy on a Tentacle you host, and proves what it finds end to end.