OSINT INTO THE SAME GRAPH

Sixteen collection tools on one Tentacle, and a ledger of which command hit which selector. No identity is resolved for you the join from handle to human is yours to argue.

What you get

Cracken's realm cybergraph after a discovery pass, showing roughly eighty hosts, services and endpoints found from a single starting domain.
Explore the
platform.
  • Resolved Selectors

    Sherlock, Maigret and Blackbird return every place a handle resolves.

  • Negative Results

    A tool that came back empty is kept and dated too.

  • Identity Graph

    People, usernames, emails and credentials sit in one graph with domains, IPs and services.

  • Run Ledger

    Hunchly records every page you landed on, tool by tool and selector by selector.

Where it stops

The catalog queries public endpoints and files you already hold. Where a tool needs an account, it uses one of yours.

  • No identity resolution. The join is yours

    Cracken does not merge four accounts into one person and never reports an identity as resolved.

  • One tool can land in the subject's inbox. Nothing else here reaches them

    There is no message, no connection request, no group join, no mail sender and no dialler.

  • No authenticating as anyone but yourself

    GHunt authenticates as a Google account signed in on your own Tentacle.

  • No access control gets bypassed

    Nothing here defeats a login wall, a paywall, a rate limit or a privacy setting.

  • Authorisation and jurisdiction are yours

    Cracken does not know what your warrant, your engagement letter or your editorial standard covers, and it will not stop you exceeding any of them.

Mechanism

Each selector has its own shelf. You take the tool off it by hand.

Twelve of these sit in the Integration Center's OSINT category; httpx and Katana are filed under recon, ExifTool and FOCA under forensics. All sixteen install onto a Tentacle the same way, and what they return is read into the same realm Cybergraph by the observer that curates it. Installation is realm-scoped and persists until you uninstall it. The five playbooks that execute on their own — Domain Recon, Web App Pentest, Network Pentest, Cloud Pentest, AD Pentest — never take a person as input.

A username: Sherlock, Maigret, Blackbird.

Three passes over the same string, because their site lists differ from each other and all three go stale between releases. Sherlock checks its maintained list and returns the profiles the handle resolves to. Maigret casts wider and pulls what the profile page itself exposes. Blackbird is the third opinion. What comes back is where the string exists, which is a shorter list than where the person is.

An email: Holehe, h8mail, GHunt.

Holehe maps which services already hold an account for the address. h8mail checks it against breach corpora. GHunt turns it into the Gaia ID behind a Google account, and inspects a Drive item when you hand it that item's link or id.

A phone number: PhoneInfoga.

It breaks the number down to country, carrier format and variants, then writes the social, disposable-number and scam-report queries around it. It runs none of them, and it never dials.

A logged-in surface: GHunt, OSINTgram.

The only two tools that need an account, and both use one you already own. GHunt reaches the Google profile behind an address. OSINTgram reaches what an Instagram account can see. Every other shelf here works off public surfaces.

A domain or a company: Amass, theHarvester, Recon-ng, Tavily, httpx, Katana.

The entity side of a person. Amass enumerates the estate, theHarvester pulls names and addresses off third parties, Recon-ng runs the modules you pick, Tavily searches, httpx says which hosts answer, Katana maps the routes including the ones JavaScript renders. These take hosts, so Trusted Targets applies: a hostname outside the list is out of scope, and you do not get to point a tool at it.

A file: ExifTool, FOCA.

ExifTool reads the metadata inside the images, audio, video and documents an operation collected. FOCA collects more of them first — the files Google, Bing and DuckDuckGo have indexed for the domain — then reads the usernames, paths and server names those files carry. The usernames go back into Sherlock and Maigret.

Who this is for

Start testing
  • Investigator

    You collect against a selector across a dozen sources, then spend the rest of the day proving where each fact came from.

  • Red Team Lead

    You want the pretext material — org chart, tooling, vocabulary, who reports to whom — gathered before the engagement rather than during it.

  • CISO

    You need to see what an adversary can assemble about your company for free, before they assemble it.

Questions

Does Cracken run OSINT automatically?

No. Five playbooks execute on their own — Domain Recon, Web App, Network, Cloud and AD Pentest — and every one of them takes infrastructure as input. None takes a person, a handle, an address or a number. The OSINT catalog is tooling: you install a tool onto a Tentacle from the Integration Center, you name the selector, and it runs on that command. Inside an operation the agent handles the mechanics — installing the tool, running it, removing it after — but the command that reaches a person comes from you. One thing to know: a scheduled automation runs an operation from a task you write, and the agent in that operation can reach the tools you installed. If a scheduled task names a person, that instruction was yours, and the operation record carries your name on it.

What does a username hit actually prove?

That the string is registered on that site. Nothing further until you do the work. Sherlock, Maigret and Blackbird check a handle against site lists that disagree with each other and age badly, so a miss is weak and a hit is a candidate. The Cybergraph keeps the candidates apart, each with its tool and its date. Merging them into one person is your judgement and belongs in your own words.

Do I need a research account to run these?

Two of the sixteen. GHunt wants a Google session signed in on your Tentacle, and OSINTgram wants an Instagram login you supply when you install it. Both are accounts you own and manage; Cracken builds neither. The tradecraft around that account is the other half of this work and has its own page at /use-cases/research-account-opsec.

How is this different from the graph tool I already run?

A desktop graph client keeps your people work in one file and your infrastructure work somewhere else. Here both land in the same Cybergraph, so an address ExifTool pulled out of a PDF sits next to the host that published the PDF and the subdomain Amass enumerated the same week. The tools also run from a Tentacle on a host you own rather than from your laptop, so the request carries that host's egress. What that egress is was fixed when the Tentacle was installed - direct, a WireGuard sidecar, or a proxy you supplied - and the tradecraft around that choice is its own page at /use-cases/research-account-opsec.

Install a Tentacle, add Sherlock from the Integration Center, and point it at one handle.

What comes back lands in the realm Cybergraph, beside the hosts. The line in the ledger has your name on it.