Features
The features you work with in Cracken, grouped by where they sit in the product loop — run the work, build up knowledge and evidence, let it run on its own and ship the results, then extend the toolset.
Run the work
Operations
How an operation runs an AI-driven security assessment — its records ledger, autonomy modes, controls, model selection, and lifecycle.
Realms
An isolated, per-tenant boundary that scopes operations, tentacles, Cybergraph, artifacts, secrets, and configuration.
Operations run through Tentacles — the core component you install on a host — and their tool actions execute in Vessels.
Knowledge and evidence
Cybergraph
Cracken's graph model of an assessment — entities as typed nodes, their relationships as typed edges — with realm and operation views.
File System
One shared store for an operation's files — tool results, command output, uploads, library and playbook content, and reports — that persists across the operation.
Autonomy and output
Monitors
Wait conditions an operation arms to watch for an outside signal — a callback, a script result, a graph change, a schedule, a child operation, or a human reply.
Semi-autonomous policy
Let the agent auto-execute actions within a trust level, scope, and exception rules you set per realm, instead of approving every action by hand.
Automations
Realm-level monitors that create an operation automatically on a CRON schedule, an inbound webhook call, or a matching Cybergraph change.
Reporting
Turn operation work into security-assessment reports — agent-written output files you download as PDF or Markdown, with attachable custom templates.
Notifications
The notification center for operation events and approval requests, with per-level control over in-app pop-ups, browser notifications, and email.
Team
Manage who has access to your tenant and what they can do — invite members and assign roles with role-based access control.
Extensibility
Playbooks
Reusable, structured methodologies you choose explicitly to drive repeatable operations.
Skills
Reusable knowledge blocks you write once and inject into the agent's system prompt during operations.
MCP servers
Give the agent extra tools and data sources during operations by starting or connecting Model Context Protocol servers on a tentacle.
Tentacle tools
Browse a catalog of installable security tools and add them to specific tentacles on top of the base Kali Linux toolkit, from the Integration Center.
Integrations
Connect your security tools so their findings and asset data flow into the Knowledge base and Cybergraph.