VaultCat
Full-lifecycle HashiCorp Vault penetration testing toolkit — recon, hijack, escalate, exfiltrate, pivot, and persist across three operational modes.
- External Recon — zero-knowledge Vault fingerprinting, TLS/CORS/header audit, version→CVE matching, auth surface mapping
- Authenticated Assessment — token capability audit, policy analysis, KV enumeration, TTL governance, auth config audit
- Local Post-Exploitation — filesystem + git credential scanning (56 patterns), cross-file correlation, AppRole/DB validation
- Active Execution — 30 state-changing modules (privilege escalation, secret exfiltration, persistence, pivot, CVE exploitation)
- AI Agent — ReAct-loop autonomous pentest agent with multi-provider LLM, attack tree walker, and mutation engine
- MCP Server — 52 tools exposed via FastMCP for Claude Desktop and other AI clients
Ethics: Use this tool only on systems you own or have explicit permission to assess. Read-only modules run freely; state-changing and destructive operations require
--confirm-active. No brute-force or password cracking.
Install
pip install vaultcat
For development:
git clone https://github.com/muhammedkurtoglu0/vaultcat.git
cd vaultcat
uv sync
uv run vaultcat chat
Quick Start
# Unauthenticated recon
vaultcat scan --target https://vault.example.com:8200
# Authenticated audit
vaultcat scan --target https://vault.example.com:8200 --token hvs.xxx --capability-audit
# Local credential hijacking
vaultcat hijack ./my-repo --validate-token --target https://vault.example.com:8200
# AI-powered pentest chat (terminal)
vaultcat chat
# AI chat with desktop GUI
vaultcat chat --ui desktop
# MCP server (for Claude Desktop integration)
vaultcat mcp
Documentation
| Guide | What it covers |
|---|---|
| Reconnaissance | Unauthenticated scanning — TLS, CORS, CVE matching, auth surface |
| Authenticated Assessment | Token-based audit — capability, policy, KV, TTL, AppRole validation |
| Credential Hijacking | File/git scanning (56 patterns), correlation, validation |
| Active Execution Modules | 30 state-changing modules with risk levels and parameters |
| AI-Powered Pentesting | Chat agent, auto mode, tree walker, stealth, web search |
| MCP Integration | Connect Claude Desktop, VS Code, and other AI clients |
| CLI Flags Reference | All 50+ flags across 5 commands |
| Architecture | Component flow, package layout, attack tree design |
| Environment Variables | LLM keys, base URLs, NVD, web search configuration |
Connect to Claude Desktop
vaultcat mcp --transport stdio
Then add to your Claude Desktop config:
{
"mcpServers": {
"vaultcat": {
"command": "vaultcat",
"args": ["mcp", "--transport", "stdio"]
}
}
}
52 pentest tools appear in Claude's toolbox. Full MCP guide →
Supported LLM Providers
| Provider | Env Var | Default Model |
|---|---|---|
| Anthropic | ANTHROPIC_API_KEY |
claude-sonnet-5 |
| DeepSeek | DEEPSEEK_API_KEY |
auto-detect |
| OpenAI | OPENAI_API_KEY |
gpt-4o-mini |
| Kimi | KIMI_API_KEY |
auto-detect |
| Ollama (local) | OLLAMA_HOST |
auto-detect |
Project Layout
main.py CLI entry point (Typer, 5 commands)
vault_cli.py Typer app definition
core/ Reporting, risk scoring, TLS config
reconnaissance/ 14 unauthenticated recon scanners
scanners/ 10 authenticated assessment scanners
credential_hijacking/ 7 file/git scanning + correlation modules
active_execution/ 30 state-changing assessment modules
modules/
cloud/ AWS/Azure/GCP exploitation
database/ DB credential harvest + exploitation
general/ CVE scanner, agent sidecar, DoS
persistence/ Backdoors + audit manipulation
pivot/ Cross-service lateral movement
seal/ Seal/unseal + key exfiltration
secrets/ KV dump, PKI, Transit, Raft storage
token/ Priv esc, token/policy exploits, K8s/JWT/AppRole
ai_core/ LLM agent, MCP server, chat UI, planning, session
vaultcat-lab/ Docker-based lab (Vault 1.15.3 + PostgreSQL 16)
tests/ 23 test files, 600+ tests
Vault Pentest Lab
cd vaultcat-lab
docker compose up -d
./scripts/setup-lab.sh
source lab-tokens.env
License
MIT — see LICENSE.
Download files
Download the file for your platform. If you're not sure which to choose, learn more about installing packages.
Source Distribution
Built Distribution
Filter files by name, interpreter, ABI, and platform.
If you're not sure about the file name format, learn more about wheel file names.
Copy a direct link to the current filters
File details
Details for the file vaultcat-1.0.2.tar.gz.
File metadata
- Download URL: vaultcat-1.0.2.tar.gz
- Upload date:
- Size: 454.3 kB
- Tags: Source
- Uploaded using Trusted Publishing? No
- Uploaded via: twine/7.0.0 CPython/3.14.0
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
783f24fa5eeec2b3546f5ae4d7499ac27f5dd0973c926cb1198fd0233993698b
|
|
| MD5 |
ab9379629d50aaecdae1333660ca2ce7
|
|
| BLAKE2b-256 |
c5329296cde595bac431c904e56be4dc848a53306487c0f9c672ffcd50eb3799
|
File details
Details for the file vaultcat-1.0.2-py3-none-any.whl.
File metadata
- Download URL: vaultcat-1.0.2-py3-none-any.whl
- Upload date:
- Size: 446.1 kB
- Tags: Python 3
- Uploaded using Trusted Publishing? No
- Uploaded via: twine/7.0.0 CPython/3.14.0
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
726b82f2fc55b30636de94b05b9b6e590db43ab97ab351c1680b497f199cddff
|
|
| MD5 |
76edfa6b3f3f870f5097b0ab18394165
|
|
| BLAKE2b-256 |
12648cf8a8f307fb6491c7d5ff7ff0a59f23e92c5ef1e35ba57757e1dbb8cf9c
|