NETWORK PENTEST FROM THE INSIDE

You learn which internal hosts one foothold reaches, and where the boundary stopped it.

Every candidate is reproduced before it counts.

Explore the
platform.
  • Service Verdicts

    Cracken enumerates the version behind each open port and tests it.

  • Boundary Crossing Results

    Each attempt records source, destination, port and observed outcome.

  • Foothold Reach

    The hosts and services one phished person's machine could touch.

  • Command-Level Evidence

    Every record carries the command that produced it, its output and captured artifacts.

Who this is for

Start testing
  • Network Security Lead

    Your segmentation diagram says those two zones cannot talk to each other. You need someone to try it rather than read it.

  • Red Team Lead

    You want the internal path from one foothold to domain admin walked and recorded, without booking a two-week engagement to get it.

  • CISO

    Your last internal test was eleven months ago. The network has changed every week since.

Questions

Do I have to install something inside my network?

Yes. This playbook runs from a Tentacle on a host in the segment you want tested. It installs with a Docker Compose, Docker run, or Podman command on Linux, macOS or Windows, and connects back to Cracken over an outbound WebSocket.

Does this replace my vulnerability scanner?

No. Cracken reads asset and vulnerability context from the scanners you already run, including Tenable, Qualys and Rapid7 InsightVM, then tries to exploit what they flagged. The scanner produces the candidate list; this playbook decides which entries are real.

Will this break something in production?

Exploitation against a live host carries real risk, which is why approval is the starting point and the scope is fixed before anything runs. On Balanced, the default preset, read-only recon runs on its own while the nmap sweep, the exploit and every cross-segment probe queue for your approval. Approval is per action, the ranges are fixed before the run, and the operation can be stopped mid-step.

Why prove exploitability when I could just patch faster?

Because prioritisation now turns on exposure and exploitation evidence rather than severity alone. This playbook produces the exposure-and-exploitability half of that answer for your internal estate.BOD 26-04, Prioritizing Security Updates Based on Risk (CISA, 10 June 2026)

Test the network you actually run.

Bring the ranges and a host to install the Tentacle on.