NETWORK PENTEST FROM THE INSIDE
You learn which internal hosts one foothold reaches, and where the boundary stopped it.
Every candidate is reproduced before it counts.
platform.
Service Verdicts
Cracken enumerates the version behind each open port and tests it.
Boundary Crossing Results
Each attempt records source, destination, port and observed outcome.
Foothold Reach
The hosts and services one phished person's machine could touch.
Command-Level Evidence
Every record carries the command that produced it, its output and captured artifacts.
Scope
A run covers service and version enumeration, default and reused credentials, unauthenticated services, segmentation between zones, and the path from one foothold to the next host. This is the network layer, worked from a host inside it. Everything below is either a different playbook or not ours at all.
No remediation. Cracken proves the path and hands you the evidence
It does not patch the host, write the firewall rule, or change a configuration.
No domain identity work
Kerberos roasting, ADCS, delegation, ACL and GPO abuse belong to the Active Directory playbook, which picks up where this one hands over a foothold.
No OT or ICS protocols
A Tentacle in a plant network still speaks IP, but Modbus, DNP3 and the safety consequences of touching them are not in this playbook.
No wireless
The playbook carries a Wi-Fi step and it depends on a host with a radio the Tentacle container can use.
No verdict on your detection stack
A crossed boundary tells you the boundary failed.
Who this is for
Start testingNetwork Security Lead
Your segmentation diagram says those two zones cannot talk to each other. You need someone to try it rather than read it.
Red Team Lead
You want the internal path from one foothold to domain admin walked and recorded, without booking a two-week engagement to get it.
CISO
Your last internal test was eleven months ago. The network has changed every week since.
Questions
Do I have to install something inside my network?
Yes. This playbook runs from a Tentacle on a host in the segment you want tested. It installs with a Docker Compose, Docker run, or Podman command on Linux, macOS or Windows, and connects back to Cracken over an outbound WebSocket.
Does this replace my vulnerability scanner?
No. Cracken reads asset and vulnerability context from the scanners you already run, including Tenable, Qualys and Rapid7 InsightVM, then tries to exploit what they flagged. The scanner produces the candidate list; this playbook decides which entries are real.
Will this break something in production?
Exploitation against a live host carries real risk, which is why approval is the starting point and the scope is fixed before anything runs. On Balanced, the default preset, read-only recon runs on its own while the nmap sweep, the exploit and every cross-segment probe queue for your approval. Approval is per action, the ranges are fixed before the run, and the operation can be stopped mid-step.
Why prove exploitability when I could just patch faster?
Because prioritisation now turns on exposure and exploitation evidence rather than severity alone. This playbook produces the exposure-and-exploitability half of that answer for your internal estate. — BOD 26-04, Prioritizing Security Updates Based on Risk (CISA, 10 June 2026)
Test the network you actually run.
Bring the ranges and a host to install the Tentacle on.





