NAME THE ACTOR RUN THEIR CHAIN

This playbook tells you which stages of that actor's chain your controls stop, and which they do not.

Why they're looking

…the testing that we've done with the pen test platforms are just massive amount of requests. They're loud, they're noisy, they do, they produce findings. But like, I can't use that on one of my campaigns.

Senior red team manager, Fortune 500 software company

What you get

Per-operation autonomy controls in Cracken, with manual, semi-automatic and automatic modes selectable for a single operation

Autonomy is set per operation. The chain runs as far as the mode you picked allows.

Explore the
platform.
  • ATT&CK-tagged action trail

    Every action Cracken took, with the command, the captured output, and the technique it maps to.

  • Cybergraph attack path

    Hosts, accounts, credentials and the edges between them.

  • Reproduction behind every finding

    The exact command and captured signal a second operation used to reproduce the access.

  • Your EDR's own alerts

    CrowdStrike, SentinelOne or Defender alerts, filtered to the hosts and hours the run touched.

Where it stops

These are hard limits written into the playbook, not defaults you can switch off. Two of them hand work back to your operator in the middle of a run.

  • No prewritten actor plans

    Cracken runs the technique set you hand it, not a scripted APT29 or FIN7 emulation.

  • No offline cracking and no password spraying

    The AD bundle has neither skill.

  • No phishing, vishing, or pretext

    A run starts from the network position and credentials you give it.

  • No remediation and no incident response

    Cracken proves the path and records a pre-existing misconfiguration as a finding.

  • Nothing is stubbed

    A technique either executes against the real estate or it does not run, and a technique outside the shipped skill set is never reported as covered.

Who this is for

Start testing
  • Red Team Lead / Threat Emulation Specialist

    You need to emulate specific threat actors against your environment — not generic attack patterns. Full kill-chain coverage, MITRE-mapped, with every step logged and replayable.

  • Pentester / Offensive Security Operator

    You're doing manual engagements but losing time on reconnaissance and pivot mechanics. You need agents that handle the kill chain execution while you focus on the high-judgment steps.

  • CISO (post-incident or board-driven)

    Leadership wants to understand what a real attacker could accomplish against your environment. You need a full adversary simulation — not a vulnerability scan — with an executive-readable output.

Questions

Can Cracken emulate a specific named group?

Cracken has no library of prewritten actor plans. You give the operation the group's technique set and objective, and Cracken runs the techniques its shipped skills cover against your estate. It will not claim to have run a technique it does not have.

How is this different from our red team retainer?

A retainer buys operator hours in blocks and books weeks ahead; this playbook runs the technique set on demand under the same written authorisation, and every recorded finding carries the command and captured signal a second operation used to reproduce it. It does not replace a red team's human-layer access or improvisation — there is no phishing, no pretext, and no plan Cracken writes for you.

Will a run change our Active Directory?

Any technique that creates a principal, changes an ACL or attribute, or enables a template must capture the original value first, restore it on completion, and re-read it to confirm the restore. If Cracken cannot prove exact rollback, the sub-operation returns a blocking cleanup failure naming every artefact still present instead of reporting success.

What happens when a technique gets blocked mid-run?

BLOCKED is not a verdict in this playbook. A candidate stopped by a missing tool, an unreachable target, or clock skew stays pending, the orchestrator clears the blocker and re-dispatches, and the operation cannot complete while any candidate is still unresolved.

Take one group's chain as far as your controls allow.

Bring the technique set you care about and a domain you are authorised to test. At the end of the run you have the ATT&CK-tagged trail, the proven column, and the unproven one.