PAST THE CLICK INTO THE DOMAIN

Why a click rate tells you who fell for it, and what a real lure would have taken.

What you get

Explore the
platform.
  • Proven attack path

    Every step from the supplied identity to the highest access it reached, with reproductions.

  • Cybergraph after the run

    Your domain as a graph of person, credential, device and service nodes, with each edge's verdict.

  • Unproven candidates

    Candidates that failed reproduction, plus paths never attempted, including anything behind offline cracking or spraying.

  • Pre-send exposure picture

    Typosquat domains, their certificates, which resolve live, which sit parked, and where they are hosted.

Where it stops

Spear phishing has two halves: the send, and everything after it. Cracken runs the second half. The first half stays with your awareness platform.

  • Cracken does not send mail to your employees

    There is no campaign sender, no template library, no click tracker and no training module.

  • Cracken does not score individual people

    No per-employee risk rating, no leaderboard, no remedial enrolment.

  • Cracken does not crack captured hashes or run password sprays

    The AD Pentest bundle carries no cracking or spraying skill, so recovered material and the lockout-policy decision go back to your operator.

  • Cracken does not remediate

    It will not revoke a token, kill a session, delete a mailbox rule or reset an account.

  • Cracken is not DFIR

    This is an authorised test against a live estate under a scope you set, not an investigation of a real intrusion.

Who this is for

Start testing
  • Security Awareness Lead

    Generic templates train people to spot generic templates. Your attackers write one message for one person.

  • Detection Engineer

    You need to know whether the mail that gets past the gateway is caught by anything downstream of it.

  • CISO

    Somebody will click. You would rather know what that costs before it happens than after.

Questions

Does Cracken send phishing emails to our employees?

No. Cracken operates no mail sender, no template library and no click tracker, and it delivers no awareness training. Keep your awareness platform for the send; Cracken runs the intrusion that follows the credential.

What do we hand over to start a reach test?

A reach test starts from one standard-user identity and the realm's active scope allowlist. The credential is stored as an encrypted realm secret and injected into execution only at call time, so it never lands in the Cybergraph or in a report.

How do we know a finding is real and not a model's guess?

Every candidate escalation is sent to a separate verification operation that re-authenticates and reproduces the access in fresh context. Only a PROVEN verdict becomes a finding; an UNPROVEN candidate is dropped or returned with its failure reason, and a BLOCKED candidate stays open work rather than passing as a clean result.

Can we stop it mid-run, or gate it action by action?

Yes. An operation can be paused, resumed or archived at any point, and a realm-scoped semi-autonomous policy decides which actions auto-execute and which wait for your approval, with a per-operation override. The model runs a no-cyber-refusal posture on authorised work, so what bounds a run is the scope and autonomy level you configure.

Find out what the click was worth.

Bring one identity and one domain. You get what it reached, with the reproduction for each step, and an honest list of what we could not prove.