Playbooks
Cracken ships thirteen capabilities and five of them execute today. What a playbook is as an object, which ones run, and what each one proves.
- 01 playbookRuns today
Web Application Penetration Testing
You get working exploits against your own web application, each one reproduced before anyone wrote it down.
- 02 playbookRuns today
Cloud Penetration Testing
You learn which cloud identities actually reach production data, and the exact role chain each one walks to get there.
- 03 playbookRuns today
External Attack Surface Discovery
You get the list of internet-facing assets you actually expose, including the ones no inventory has.
- 04 playbookRuns today
Active Directory Attack Path Validation
You get the paths to Domain Admin that actually hold, and the command that proved each one.
- 05 playbookModule
AI Penetration Testing Platform
This playbook hands your engineers exploits they can re-run, not a list of things that might be exploitable.
- 06 playbookModule
Application Vulnerability Validation
This playbook cuts the application security backlog down to the findings an attacker can actually reach.
- 07 playbookModule
Adversary Simulation
This playbook tells you which stages of that actor's chain your controls stop, and which they do not.
- 08 playbookModule
Social Engineering Testing
This playbook shows which channel gets a stranger through, and which procedure let them.
- 09 playbookModule
Threat Intelligence Validation
This playbook separates the threat-feed items usable against you from the ones you can stop carrying.
- 10 playbookModule
Malware Analysis
This playbook establishes what a file does on a host you own, without giving custody of the sample to anyone.
- 11 playbookModule
Digital Forensics
This playbook shows how much of a real attack your hosts recorded, when you already know what was done to them.
- 12 playbookGuide
Spear Phishing Simulation
Why a click rate tells you who fell for it, and what a real lure would have taken.
- 13 playbookGuide
Adversarial Exposure Validation (AEV)
The case for attacking your open findings instead of ranking them, and which playbooks do it today.
- 14 playbookGuide
Research Account OPSEC
A research account that does not resolve back to you, and an exit address that is revocable and on the record.
- 15 playbookGuide
OSINT Investigations
Sixteen collection tools on one Tentacle, and a ledger of which command hit which selector. No identity is resolved for you — the join from handle to human is yours to argue.
One question per run. The answer holds or it does not.
A scanner sweeps everything and ranks what it finds. A playbook takes one question — can this application be broken into, does this domain reach an admin path, is this alert exploitable — and works it until something proves or fails to prove. You pick the question. What comes back is a reproduction or a NOT PROVEN, never a severity guess.
Underneath, a playbook is a stored recipe held as a version: a system prompt with its pinned tools and integrations, scoped to one realm. A Tentacle hosts the run and writes what it learns into the Cybergraph, so the next playbook starts from what the last one established rather than from nothing.
Five of thirteen execute. The other eight you can buy, not yet run.
The grid below lists seventeen: these thirteen, plus adversarial exposure validation, which is the category rather than a capability in it; two pages on collection tradecraft; and a second page on the social engineering module, because phishing is the half of it people search for by name.
Executes today
Sold as a module, does not execute yet
- Org Threat Intel
- Application Security
- Digital Forensics
- Malware Research
- Red Team Ops
- Social Engineering
- OT/ICS Security
- AI/LLM Security
The eight sit on the launch screen behind Talk to sales. Buying one gets you the engagement; it does not start an operation, because there is no recipe behind it yet. Ask what a module covers today.
Pick the one that matches your question.
Five playbooks run today and eight modules are sold ahead of the recipe behind them. A scoping call sorts which of the two your problem needs, before anyone books anything.

