TEST THE PLANT AT A SET CEILING

This playbook tests the one network you have never run an attacker at, only as far as a limit you set first.

What you get

Explore the
platform.
  • Purdue level ceiling

    L0 to L4 is a setting you pick before the run, not a contract clause.

  • Blocked action ledger

    Every refused action is logged with the command, the level it scored, and who denied it.

  • Reproducible findings

    Each finding carries the command, its output, the artifact left behind, and MITRE ATT&CK references.

  • Unvalidated credentials

    Credentials the ceiling blocked us from testing on vendor remote access come back unvalidated, not paths.

Where it stops

In an industrial environment the limits are the product.

  • Nothing reaches a controller

    No logic download, no register write, no firmware operation against a PLC, RTU or safety instrumented system.

  • It does not test the IT-to-OT crossing itself

    The boundary, its conduits, and the pivot across them are a separate playbook and a separate scope.

  • It validates exposure

    It does not remediate, patch, reconfigure a firewall, or respond to an incident.

  • It is no substitute for a process-safety assessment

    Cracken has no view of the process, the interlocks, or what any given state change would do to the plant.

Who this is for

Start testing
  • OT Security Lead / ICS Engineer

    The IT/OT boundary is where nation-state actors pivot into operational systems. You need testing that understands ICS/SCADA protocols and validates segmentation without risking availability.

  • CISO (Critical Infrastructure / Utilities / Energy)

    Regulators expect demonstrated resilience at the IT/OT boundary. You need evidence of boundary testing that satisfies IEC 62443, NERC CIP, and similar frameworks.

  • Head of Security / Critical Infrastructure

    A breach that crosses from IT into OT isn't a data breach — it's an operational incident. You need adversarial validation of the boundary.

Questions

Can this run against a live production process?

Cracken does not decide that — the intrusiveness ceiling and the Trusted Targets list do, and both are set before the operation starts. At L1 the operation is limited to read-only requests, and selecting the Cautious preset disables command execution entirely. Whether that is acceptable for a given process is the operator's call, made in a setting rather than in a conversation.

Does anything leave our network?

That depends on the deployment. A Tentacle runs on a host you own and its egress can be direct, through a proxy, or over a WireGuard tunnel with an iptables killswitch. Cracken itself can be deployed on-premises or fully air-gapped, which requires either a reachable model endpoint or enough local compute to host models; without live model access, output quality is somewhat reduced.

Who runs the operation?

Your team does. Cracken's security-specialised model executes the commands, but the scope, the ceiling, the approvals, and the stop are held by your operator, and every action, approval, and denial is recorded in the ledger with the command and the decision.

Has an attacker actually taken control of a process, or is this a hypothetical?

It has happened. Seven US federal agencies documented Iranian-affiliated actors disrupting programmable logic controllers across water, energy and government facilities through project-file manipulation and tampering with HMI and SCADA displays, resulting in operational disruption and financial loss. Cracken's OT/ICS playbook tests the supervisory side of the boundary that campaign crossed, as far as the ceiling you set.Cybersecurity Advisory AA26-097A, Iranian-Affiliated Cyber Actors Exploit Programmable Logic Controllers Across US Critical Infrastructure (AA26-097A, FBI, CISA, NSA, EPA, DOE, US Cyber Command (CNMF) and Treasury, 7 April 2026, last updated 22 July 2026)

Test the plant at a ceiling you set.

Run this playbook under a ceiling you set, or tell us what your plant estate looks like.