ADVERSARIAL EXPOSURE VALIDATION

The case for attacking your open findings instead of ranking them, and which playbooks do it today.

Why they're looking

Sometimes we pull out the old, the previously done pen test, blow the dust off and… it might have been years. And you can tell, right? You can tell by having a look at some of our services.

CISO, European logistics group

The playbooks that do it today

A realm dashboard showing entity and relationship counts, an entity map of connected assets, and a list of high findings with their names.

A realm after a validation run: the estate as a graph, and the findings that earned a verdict.

Explore the
platform.
  • Web App Pentest

    Injection, auth and access control against a running application.

  • Network Pentest

    Reachability and exploitation across an internal estate.

  • AD Pentest

    Kerberos, delegation and ACL paths through Active Directory.

  • Cloud Pentest

    Identity and role assumption paths through a cloud account.

  • Domain Recon

    The external asset picture, built passively, handed to whatever runs next.

Where it stops

Adversarial exposure validation answers one question: which of the exposures you already know about can be reached and used. Everything below is a different question, and some of them are a different Cracken playbook.

  • It does not emulate a named threat actor

    If you want to know whether you survive one group's chain end to end, that is adversary simulation, and it is a different run with a different report.

  • It does not measure detection

    Nothing here tells you what your EDR, SIEM or analysts saw while the attack ran.

  • It does not remediate

    Cracken proves the exposure and hands you the route that reached it.

  • It does not discover exposures your sources never reported

    This playbook validates the inventory you bring it; finding what nobody has reported is reconnaissance and penetration testing work.

  • It does not take code-scanner alerts

    SAST, SCA and secret-scanning findings are a separate import surface this flow does not read.

Who this is for

Start testing
  • Vulnerability Management Lead

    Your backlog is in the thousands. Your engineering team tunes you out because you can't tell them which vulnerabilities matter.

  • Red Team Lead

    You want to know exactly which exposures in your environment an attacker could actually reach from the outside.

  • CISO

    "We have 4,000 open findings" is not an answer the board can act on. You need to present a prioritized, defensible view of what's actually reachable and what's noise.

Questions

What proves a vulnerability is exploitable rather than just scoring it?

Running the attack. A CVSS score is a property of the vulnerability; exploitability is a property of your environment — the control in front of it, the credential that reaches it, the segment it sits in. Cracken takes the exposures already in your scanners, cloud posture tools and identity sources and works each one against your live estate under a scope you set, and records a finding only where the attack landed. Everything else stays a candidate with the reason it failed.

Does adversarial exposure validation replace a penetration test?

No. Adversarial exposure validation starts from an exposure list you already hold and returns a verdict on each item; a penetration test starts from a target and hunts for what nobody has reported yet. The methods overlap heavily — both execute against the live system rather than inferring from a score — and Cracken runs both.NIST SP 800-115, Technical Guide to Information Security Testing and Assessment (NIST, September 2008)

Can Cracken run this against production?

Yes, inside a policy you set on the realm before anything runs. Trust levels range from Cautious, where command execution is off entirely, to Aggressive, where scoped exploits run without a pause and destructive actions still wait for a person. You define the trusted targets, you can override the policy for a single operation, and you can stop the operation at any point.

Why validate exposures I already know about instead of hunting for new ones?

Because the ones you already know about are what gets used. In the campaign that 23 agencies across 13 countries co-sealed an advisory about, the actors had considerable success exploiting publicly known CVEs and other avoidable weaknesses, and exploitation of zero-day vulnerabilities was not observed at all. The gap was never discovery. It was that nobody had established which of the known findings actually worked.Joint Cybersecurity Advisory AA25-239A, Countering Chinese State-Sponsored Actors Compromise of Networks Worldwide to Feed Global Espionage System (AD25-239A, CISA, NSA, FBI and 20 other authoring and co-sealing agencies across 13 countries, 3 September 2025 (last revised))

Find out which of your open findings actually works.

Connect the tools you already run, name a scope, and get a verdict per exposure. Start self-serve, or talk to the team about a scoped run against production.