Skip to main content

Integrations

Connect your existing security stack to Cracken and turn it into operation context and action. Data integrations that support imports bring selected findings and assets into the Knowledge base and Cybergraph so operations can seed scope, prioritize work, and avoid re-testing known issues. Identity integrations provide live user and group queries to operations. Where a connection supports actions, Cracken can also query the source or launch work such as a new scan from the operation.

Step-by-step instructions
  1. Open the Integration Center and select the Data Integrations tab.
  2. On the provider card for your tool, click Install (or Configure if it's already set up).
  3. Enter the vendor's connection credentials (for example, a client key and secret key). Optionally click Test Connection to verify them first.
  4. Click Save & Connect. Once the connection reads Active, the dialog opens the Vulnerability Findings tab.
  5. Click Fetch Vulnerability Findings to pull the synced findings, then add the ones you want to the realm's Cybergraph.

At a glance

  • What it is — A governed connection from a realm to an external security tool, available to both the Integration Center and Cracken operations.
  • When to use it — Bring scanner, EDR, application-security, identity, cloud-posture, or asset-inventory context into the same workflow that acts on it.
  • Inputs — A vendor selection (from the supported vulnerability scanner, EDR, and cloud security posture sources) and its connection credentials (for example a client key and secret key).
  • Outputs — Imported findings, CVE/severity data, and asset/infrastructure records where the provider supports sync, plus live queries and operation actions supported by the connection.
  • Related objectsCybergraph, MCP Servers, Tentacle Tools, Realms
  • Common actions — Connect a tool, sync selected data, query findings, and run supported actions such as triggering a scan.
  • API / tool links — Configure the connection in the UI; Cracken exposes its supported actions to operations automatically.

Supported tool types

Cracken connects to your security stack by category rather than to one fixed product:

  • Vulnerability scanners — pull CVEs, vulnerability findings, severity scores, and affected assets.
  • Code and application security — import findings from your SAST/SCA tooling.
  • Cloud security — bring in posture findings and misconfigurations from your cloud security tooling.
  • Asset and attack-surface sources — sync host, IP, cloud-resource, and application inventory.
  • Identity providers — query users and groups live from an operation without first copying the directory into the Knowledge base.

From connected data to operation action

Cracken does more than display imported findings:

  1. Unifies context — selected findings and assets land in the realm's Knowledge base and Cybergraph.
  2. Makes it operational — operations can use that context to plan testing, focus on important gaps, and preserve what the team already knows.
  3. Exposes supported actions — connected tools can become operation tools for listing findings, querying assets, or launching scans when the integration supports it.
  4. Handles the connection path — you choose the tool and provide its credentials; Cracken supplies only the actions and filters that connection can execute.

The result is a continuous loop between existing security telemetry and active assessment work rather than another isolated dashboard.

Supported data integrations

Open the setup guide for the tool you want to connect before creating its credential. Each guide lists the fields shown by Cracken and the vendor-side settings, roles, scopes, and resource access that credential needs.

Vulnerability management

Endpoint detection and response

Application and cloud security

Identity and attack surface

Availability

The Data Integrations screen is the source of truth for which tools are enabled and the current connection or configuration state in your environment. A connected integration advertises its provider actions and filters, while the exact tools available to an operation can be narrowed by its active playbook and capability scope. Confirm the operation's available actions in its tool surface before relying on them.

If a tool is unavailable, the configuration dialog shows a warning in place of the credential fields:

<Tool name> isn't available on this deployment yet. Ask your admin to enable it.

There is nothing to fill in and nothing to save while that warning is shown. Ask your administrator which integrations are enabled for the deployment.

You can spot the state before opening the dialog: the tool's card in the Data Integrations grid reads Ask your admin to enable it where a connectable tool reads Not configured, and its Install button is disabled.

If a setup guide describes an action that your screen does not show, contact your administrator or Cracken account representative before relying on it in an operation.

How data flows

  1. Connect a tool — install a provider from the Integration Center's Data Integrations tab and provide its credentials.
  2. Import or query — providers with a findings workflow can sync selected findings and assets; identity providers expose live user and group queries instead.
  3. Land imported data in the Knowledge base — selected findings and assets are stored in your Realm's Knowledge base and represented in the Cybergraph.
  4. Use during assessments — operations combine persisted findings and assets with the connection's live queries and supported actions.

What gets imported

Findings and vulnerabilities

  • Vulnerability scan results
  • CVE details and severity scores
  • Affected assets and systems
  • Remediation status

Assets and infrastructure

  • Host and IP information
  • Cloud resources
  • Application inventory

Set up an integration

  1. Open the Integration Center and select the Data Integrations tab.
  2. Install a provider and provide the tool's credentials.
  3. If the provider supports findings import, fetch and select the data to add to the Cybergraph.
  4. Use the imported context or the provider's live operation actions during an assessment.

Once configured, Cracken uses the data to inform its testing approach, avoid duplicating work on known issues, and act through the integration where supported.

Next steps

  • Cybergraph — where imported findings and assets land as graph state.
  • MCP Servers — extend the agent with MCP tools from the same Integration Center.
  • Tentacle Tools — install command-line tools the agent runs on a Tentacle.
  • Realms — the boundary that scopes saved integration credentials.