
Cracken + Wiz
Wiz reads your cloud accounts through the provider's APIs and snapshots to work out which resources are at risk. Cracken attacks the findings it raises. You get back the ones an attacker can turn into real impact.
Connecting Wiz
- Connect with
A Wiz service-account client ID and client secret, plus your tenant's Wiz authentication (token) URL
- Cadence
Syncs on a schedule — every 6 hours by default
- Requires
The hosted connection service enabled on your deployment — always on for Cracken-hosted workspaces
What Cracken gets from Wiz
Cloud security posture findings with severity (critical, high, medium, low, info) and state (open, resolved, snoozed)
The cloud resource the finding sits on — resource type plus resource id or name
cve list with cvss_base_score, cvss_vector and cvss_version where Wiz carries them
device — hostnames, ipv4s, tags — landed as a Device node that contains the Finding
first_seen, last_seen and state_updated_at
solution, patchable, category and vulnerability_url
vendor_id and vendor_severity, Wiz's own labels beside the normalized ones
What Wiz does not do
Cracken reads Wiz's cloud and vulnerability findings only. Wiz Code, its code-scanning product, is not connected, so those findings never arrive. The connection is read-only and one action wide: there is no scan to trigger, and no way to resolve, ignore or reassign a Wiz issue from Cracken.
How Cracken uses Wiz
- 01
Connect Wiz
- 02
Sync the cloud findings
- 03
Attack them in the account
- 04
Confirm it connected
Frequently asked questions
Does Cracken need agents in my cloud accounts to use Wiz data?
No: Cracken reads Wiz's findings over its API with a service-account client ID, client secret, and authentication URL, and deploys nothing into your accounts.
Does Cracken change anything in Wiz?
No: it only lists cloud security findings; it doesn't resolve, snooze, or reopen issues, alter Wiz policies or the Security Graph, or launch scans.
“I've been pretty impressed with how CrackenAGI is able to do its vulnerability discovery, enumeration, reconnaissance, as well as eventually being able to actually execute different exploitation paths.”
More integrations

Microsoft Defender for Cloud
Cracken proves which Microsoft Defender for Cloud recommendations an attacker can exploit.

Orca Security
Cracken proves which Orca Security findings an attacker can reach on the running workload.

CrowdStrike Falcon
Cracken shows what CrowdStrike Falcon caught and missed against real attacks.
Attack with real Wiz context.
See how Cracken works what Wiz already knows into attack paths it proves end to end.


