VaultCat
Full-lifecycle HashiCorp Vault penetration testing toolkit — recon, hijack, escalate, exfiltrate, pivot, and persist across three operational modes.
- External Recon — zero-knowledge Vault fingerprinting, TLS/CORS/header audit, version→CVE matching, auth surface mapping
- Authenticated Assessment — token capability audit, policy analysis, KV enumeration, TTL governance, auth config audit
- Local Post-Exploitation — filesystem + git credential scanning (56 patterns), cross-file correlation, AppRole/DB validation
- Active Execution — 30 state-changing modules (privilege escalation, secret exfiltration, persistence, pivot, CVE exploitation)
- AI Agent — ReAct-loop autonomous pentest agent with multi-provider LLM, attack tree walker, and mutation engine
- MCP Server — 52 tools exposed via FastMCP for Claude Desktop and other AI clients
Ethics: Use this tool only on systems you own or have explicit permission to assess. Read-only modules run freely; state-changing and destructive operations require
--confirm-active. No brute-force or password cracking.
Install
pip install vaultcat
For development:
git clone https://github.com/muhammedkurtoglu0/vaultcat.git
cd vaultcat
uv sync
uv run vaultcat chat
Quick Start
# Unauthenticated recon
vaultcat scan --target https://vault.example.com:8200
# Authenticated audit
vaultcat scan --target https://vault.example.com:8200 --token hvs.xxx --capability-audit
# Local credential hijacking
vaultcat hijack ./my-repo --validate-token --target https://vault.example.com:8200
# AI-powered pentest chat (terminal)
vaultcat chat
# AI chat with desktop GUI
vaultcat chat --ui desktop
# MCP server (for Claude Desktop integration)
vaultcat mcp
Documentation
| Guide | What it covers |
|---|---|
| Reconnaissance | Unauthenticated scanning — TLS, CORS, CVE matching, auth surface |
| Authenticated Assessment | Token-based audit — capability, policy, KV, TTL, AppRole validation |
| Credential Hijacking | File/git scanning (56 patterns), correlation, validation |
| Active Execution Modules | 30 state-changing modules with risk levels and parameters |
| AI-Powered Pentesting | Chat agent, auto mode, tree walker, stealth, web search |
| MCP Integration | Connect Claude Desktop, VS Code, and other AI clients |
| CLI Flags Reference | All 50+ flags across 5 commands |
| Architecture | Component flow, package layout, attack tree design |
| Environment Variables | LLM keys, base URLs, NVD, web search configuration |
Connect to Claude Desktop
vaultcat mcp --transport stdio
Then add to your Claude Desktop config:
{
"mcpServers": {
"vaultcat": {
"command": "vaultcat",
"args": ["mcp", "--transport", "stdio"]
}
}
}
52 pentest tools appear in Claude's toolbox. Full MCP guide →
Supported LLM Providers
| Provider | Env Var | Default Model |
|---|---|---|
| Anthropic | ANTHROPIC_API_KEY |
claude-sonnet-5 |
| DeepSeek | DEEPSEEK_API_KEY |
auto-detect |
| OpenAI | OPENAI_API_KEY |
gpt-4o-mini |
| Kimi | KIMI_API_KEY |
auto-detect |
| Ollama (local) | OLLAMA_HOST |
auto-detect |
Project Layout
main.py CLI entry point (Typer, 5 commands)
vault_cli.py Typer app definition
core/ Reporting, risk scoring, TLS config
reconnaissance/ 14 unauthenticated recon scanners
scanners/ 10 authenticated assessment scanners
credential_hijacking/ 7 file/git scanning + correlation modules
active_execution/ 30 state-changing assessment modules
modules/
cloud/ AWS/Azure/GCP exploitation
database/ DB credential harvest + exploitation
general/ CVE scanner, agent sidecar, DoS
persistence/ Backdoors + audit manipulation
pivot/ Cross-service lateral movement
seal/ Seal/unseal + key exfiltration
secrets/ KV dump, PKI, Transit, Raft storage
token/ Priv esc, token/policy exploits, K8s/JWT/AppRole
ai_core/ LLM agent, MCP server, chat UI, planning, session
vaultcat-lab/ Docker-based lab (Vault 1.15.3 + PostgreSQL 16)
tests/ 23 test files, 600+ tests
Vault Pentest Lab
cd vaultcat-lab
docker compose up -d
./scripts/setup-lab.sh
source lab-tokens.env
License
MIT — see LICENSE.
Release files for vaultcat 1.1.2
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| vaultcat-1.1.2.tar.gz | 463.9 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| vaultcat-1.1.2-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 918.3 kB
Release files / vaultcat-1.1.2.tar.gz
| Download URL | vaultcat-1.1.2.tar.gz |
|---|---|
| Size | 463.9 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
66e5e50725521746fe290a58bf7386d2f3ffe8ce3db7c1aeab877bbe1dd12859
|
|
BLAKE2b-256 checksum How to use checksums |
bea49cb839d1bcbb87ed24471a9b8bd9d46f85fee4e8dccf90e4a9196bbab616
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
uv/0.11.17 {"installer":{"name":"uv","version":"0.11.17","subcommand":["publish"]},"python":null,"implementation":{"name":null,"version":null},"distro":null,"system":{"name":null,"release":null},"cpu":null,"openssl_version":null,"setuptools_version":null,"rustc_version":null,"ci":null}
|
Release files / vaultcat-1.1.2-py3-none-any.whl
| Download URL | vaultcat-1.1.2-py3-none-any.whl |
|---|---|
| Size | 454.4 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
23b226c301accddbc1c0dd373395384767ebb6fcff240d61a390700fa1e3776e
|
|
BLAKE2b-256 checksum How to use checksums |
62123500450a12579b8450cbce81faa62afabd1aa69a05e527f0bce75024a7a9
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
uv/0.11.17 {"installer":{"name":"uv","version":"0.11.17","subcommand":["publish"]},"python":null,"implementation":{"name":null,"version":null},"distro":null,"system":{"name":null,"release":null},"cpu":null,"openssl_version":null,"setuptools_version":null,"rustc_version":null,"ci":null}
|