THE LEGEND IS YOURS. THE EXIT IP IS PINNED.

A research account that does not resolve back to you, and an exit address that is revocable and on the record.

What you get

Explore the
platform.
  • Identity Graph

    People, usernames, emails and credentials sit in one graph with domains, IPs and services.

  • Run Ledger

    Hunchly records every page you landed on, tool by tool and selector by selector.

  • Exit Address

    Set at install: direct, your own proxy, or a WireGuard sidecar with an iptables killswitch.

  • Raw Tool Output

    The agent reads Maigret's terminal output as-is in the step that picks the next command.

Where it stops

Cover, backstop, warming and retirement live outside this product and backstopping stops where documents start. An address and a number that answer are tradecraft; a fabricated identity document is a separate offence in every jurisdiction named on this page. These are the lines Cracken does not cross.

  • Never a real person's name, and never a real person's face

    A photo lifted from someone's profile makes them the cover for an operation they never agreed to, and a reverse image search returns them rather than you.

  • No account you did not create

    This is a condition of use, not something the product detects a stolen login stored against a tool looks exactly like one you built, so the rule sits with you.

  • No persona management. None

    There is no persona register, no account creation, no warming and no rotation anywhere in the product.

  • No fingerprint control, and no anti-detect browser

    The Browser Vessel is headless Chromium, and Cracken's own docs say some sites detect that.

  • No engagement. Reading only

    Cracken has no DM, no connection request, no group join and no mail sender.

  • Authorisation is yours, and so is the jurisdiction

    In the UK, a public-authority officer who forms a covert relationship with a subject a Facebook friendship counts may be acting as a CHIS under RIPA, which has to be authorised in advance with a risk assessment attached.

Controls

Managed attribution has four layers. Cracken configures two of them on hardware you own.

Separated identity and disciplined behaviour are yours. The isolated machine and the controlled exit are configuration.

An exit you fixed at install, and can revoke.

A Tentacle is a Kali Linux container on infrastructure you control, and its traffic mode is chosen when you generate the install command: Direct, a proxy you supply, or a WireGuard sidecar with an iptables killswitch pinned to one address you can place and revoke. Proxy mode is best-effort and not a network boundary — it does not cover raw sockets, DNS or QUIC. Blackbird's checks, Holehe's requests and theHarvester's queries go out through whichever you picked, rather than a shared vendor address.

One realm per investigation.

A realm scopes operations, Tentacles, Cybergraph, artifacts, secrets and configuration, and one realm's data is not visible from another. Investigation-specific work does not bleed into the alter-ego work sitting in the next realm.

Credentials referenced, never printed.

Realm secrets resolve as {{secret:<service>.<field>}} only at execution time; agents and operation history see the reference, not the value. Input that looks like secret material is blocked before it enters operation context — the default is Block & prompt to save.

Passive by ceiling, not by good intentions.

Intrusiveness is scored L0, no network contact, through L4, irreversible, and the ceiling is set before the run. Trusted Targets lists the hostnames, IPs, CIDRs and wildcard domains that actions may target automatically; anything outside that list queues for approval instead of running. New realms ship on the Balanced preset.

Read-only until you say otherwise.

Under EVIDENCE_ONLY the Browser Vessel navigates, snapshots, screenshots and reads network requests on its own; any page interaction waits for approval. Out-of-scope navigations — link-local addresses, metadata IPs — are rejected in either mode.

The agent installs the tool, uses it, and takes it off again.

Amass, Blackbird, GHunt, h8mail, Holehe, Maigret, OSINTgram, PhoneInfoga, Recon-ng, Sherlock, Tavily and theHarvester are all things you could install yourself. What you cannot do yourself is have them arrive on the right Tentacle mid-operation, run under one intrusiveness ceiling and one allowlist, and come off afterwards to keep the tentacle clean. h8mail's API keys and local dump files stay in your environment. Tavily is the exception: search terms and fetch URLs leave for its API, on your account and your key.

Who this is for

Start testing
  • Investigator

    Your research accounts leak. Reused fingerprints, matching timing and one careless login connect every one of them back to you.

  • Red Team Lead

    You need personas that survive contact — infrastructure that holds up when somebody on the other side checks it.

  • Head of Security

    An attributable research account is an incident. You need that discipline enforced rather than remembered.

Questions

Where does the collection traffic actually come from?

From the Tentacle — a Kali Linux container on a host you own. Traffic mode is fixed when the install command is generated: Direct, a proxy you supply, or a WireGuard sidecar with an iptables killswitch. Proxy mode is best-effort and explicitly not a network boundary; raw sockets, DNS and QUIC go around it. Cracken supplies no proxies, no residential pool and no exit nodes.

How do I stop a tool reaching past my authorisation?

Trusted Targets, set before the first request. Anything outside the list queues for your approval instead of running, and an out-of-scope navigation is rejected whichever browser mode you picked. Cap intrusiveness at L2 and the ceiling holds for the whole operation. The boundary exists before collection starts rather than being reconstructed from logs afterwards.

How do I keep two investigations from touching each other?

One realm each. A realm is a per-tenant boundary scoping operations, Tentacles, Cybergraph, artifacts, secrets and configuration, and one realm's data is not visible from another — that covers the machine and the record. It does not cover the bridge that actually burns investigators, which sits on your own desk: a single shared browser profile, download folder, cloud account or password manager. Cross-contamination fails at the bridge, so it takes every persona behind it at once rather than one.

Can I just buy an aged account?

No, and the reason is provenance rather than squeamishness. Bulk supply is farmed or hijacked and you cannot tell which you got. Farmed accounts are built with CAPTCHA-solving services and fabricated identity data, and die with their whole cohort when the platform finds one. A hijacked account belongs to a living person, so logging into it is unauthorized access under CFAA §1030 and Computer Misuse Act 1990 s.1 — complete in the UK whether or not you get in. Paying for it carries its own exposure: an anonymous seller cannot be screened against the SDN list, and OFAC liability is strict, so failing to identify a blocked counterparty is itself the violation. The evidentiary problem outlasts all of it. A bought account has no creation record and a history of unlogged activity by people you cannot name, which is exactly what the Berkeley Protocol requires you to be able to produce.

Install a Tentacle on your own host and set its egress mode before the first query.

You bring the account and the legend. Cracken brings the tentacle, the realm scope, and the record of what ran.