PAST THE CLICK INTO THE DOMAIN
Why a click rate tells you who fell for it, and what a real lure would have taken.
What you get
platform.
Proven attack path
Every step from the supplied identity to the highest access it reached, with reproductions.
Cybergraph after the run
Your domain as a graph of person, credential, device and service nodes, with each edge's verdict.
Unproven candidates
Candidates that failed reproduction, plus paths never attempted, including anything behind offline cracking or spraying.
Pre-send exposure picture
Typosquat domains, their certificates, which resolve live, which sit parked, and where they are hosted.
Where it stops
Spear phishing has two halves: the send, and everything after it. Cracken runs the second half. The first half stays with your awareness platform.
Cracken does not send mail to your employees
There is no campaign sender, no template library, no click tracker and no training module.
Cracken does not score individual people
No per-employee risk rating, no leaderboard, no remedial enrolment.
Cracken does not crack captured hashes or run password sprays
The AD Pentest bundle carries no cracking or spraying skill, so recovered material and the lockout-policy decision go back to your operator.
Cracken does not remediate
It will not revoke a token, kill a session, delete a mailbox rule or reset an account.
Cracken is not DFIR
This is an authorised test against a live estate under a scope you set, not an investigation of a real intrusion.
Who this is for
Start testingSecurity Awareness Lead
Generic templates train people to spot generic templates. Your attackers write one message for one person.
Detection Engineer
You need to know whether the mail that gets past the gateway is caught by anything downstream of it.
CISO
Somebody will click. You would rather know what that costs before it happens than after.
Questions
Does Cracken send phishing emails to our employees?
No. Cracken operates no mail sender, no template library and no click tracker, and it delivers no awareness training. Keep your awareness platform for the send; Cracken runs the intrusion that follows the credential.
What do we hand over to start a reach test?
A reach test starts from one standard-user identity and the realm's active scope allowlist. The credential is stored as an encrypted realm secret and injected into execution only at call time, so it never lands in the Cybergraph or in a report.
How do we know a finding is real and not a model's guess?
Every candidate escalation is sent to a separate verification operation that re-authenticates and reproduces the access in fresh context. Only a PROVEN verdict becomes a finding; an UNPROVEN candidate is dropped or returned with its failure reason, and a BLOCKED candidate stays open work rather than passing as a clean result.
Can we stop it mid-run, or gate it action by action?
Yes. An operation can be paused, resumed or archived at any point, and a realm-scoped semi-autonomous policy decides which actions auto-execute and which wait for your approval, with a per-operation override. The model runs a no-cyber-refusal posture on authorised work, so what bounds a run is the scope and autonomy level you configure.
Find out what the click was worth.
Bring one identity and one domain. You get what it reached, with the reproduction for each step, and an honest list of what we could not prove.





