VaultCat
Full-lifecycle HashiCorp Vault penetration testing toolkit — recon, hijack, escalate, exfiltrate, pivot, and persist across three operational modes.
- External Recon — zero-knowledge Vault fingerprinting, TLS/CORS/header audit, version→CVE matching, auth surface mapping
- Authenticated Assessment — token capability audit, policy analysis, KV enumeration, TTL governance, auth config audit
- Local Post-Exploitation — filesystem + git credential scanning (56 patterns), cross-file correlation, AppRole/DB validation
- Active Execution — 30 state-changing modules (privilege escalation, secret exfiltration, persistence, pivot, CVE exploitation)
- AI Agent — ReAct-loop autonomous pentest agent with multi-provider LLM, attack tree walker, and mutation engine
- MCP Server — 52 tools exposed via FastMCP for Claude Desktop and other AI clients
Ethics: Use this tool only on systems you own or have explicit permission to assess. Read-only modules run freely; state-changing and destructive operations require
--confirm-active. No brute-force or password cracking.
Install
pip install vaultcat
For development:
git clone https://github.com/muhammedkurtoglu0/vaultcat.git
cd vaultcat
uv sync
uv run vaultcat chat
Quick Start
# Unauthenticated recon
vaultcat scan --target https://vault.example.com:8200
# Authenticated audit
vaultcat scan --target https://vault.example.com:8200 --token hvs.xxx --capability-audit
# Local credential hijacking
vaultcat hijack ./my-repo --validate-token --target https://vault.example.com:8200
# AI-powered pentest chat (terminal)
vaultcat chat
# AI chat with desktop GUI
vaultcat chat --ui desktop
# MCP server (for Claude Desktop integration)
vaultcat mcp
Documentation
| Guide | What it covers |
|---|---|
| Reconnaissance | Unauthenticated scanning — TLS, CORS, CVE matching, auth surface |
| Authenticated Assessment | Token-based audit — capability, policy, KV, TTL, AppRole validation |
| Credential Hijacking | File/git scanning (56 patterns), correlation, validation |
| Active Execution Modules | 30 state-changing modules with risk levels and parameters |
| AI-Powered Pentesting | Chat agent, auto mode, tree walker, stealth, web search |
| MCP Integration | Connect Claude Desktop, VS Code, and other AI clients |
| CLI Flags Reference | All 50+ flags across 5 commands |
| Architecture | Component flow, package layout, attack tree design |
| Environment Variables | LLM keys, base URLs, NVD, web search configuration |
Connect to Claude Desktop
vaultcat mcp --transport stdio
Then add to your Claude Desktop config:
{
"mcpServers": {
"vaultcat": {
"command": "vaultcat",
"args": ["mcp", "--transport", "stdio"]
}
}
}
52 pentest tools appear in Claude's toolbox. Full MCP guide →
Supported LLM Providers
| Provider | Env Var | Default Model |
|---|---|---|
| Anthropic | ANTHROPIC_API_KEY |
claude-sonnet-5 |
| DeepSeek | DEEPSEEK_API_KEY |
auto-detect |
| OpenAI | OPENAI_API_KEY |
gpt-4o-mini |
| Kimi | KIMI_API_KEY |
auto-detect |
| Ollama (local) | OLLAMA_HOST |
auto-detect |
Project Layout
main.py CLI entry point (Typer, 5 commands)
vault_cli.py Typer app definition
core/ Reporting, risk scoring, TLS config
reconnaissance/ 14 unauthenticated recon scanners
scanners/ 10 authenticated assessment scanners
credential_hijacking/ 7 file/git scanning + correlation modules
active_execution/ 30 state-changing assessment modules
modules/
cloud/ AWS/Azure/GCP exploitation
database/ DB credential harvest + exploitation
general/ CVE scanner, agent sidecar, DoS
persistence/ Backdoors + audit manipulation
pivot/ Cross-service lateral movement
seal/ Seal/unseal + key exfiltration
secrets/ KV dump, PKI, Transit, Raft storage
token/ Priv esc, token/policy exploits, K8s/JWT/AppRole
ai_core/ LLM agent, MCP server, chat UI, planning, session
vaultcat-lab/ Docker-based lab (Vault 1.15.3 + PostgreSQL 16)
tests/ 23 test files, 600+ tests
Vault Pentest Lab
cd vaultcat-lab
docker compose up -d
./scripts/setup-lab.sh
source lab-tokens.env
License
MIT — see LICENSE.
Release files for vaultcat 1.0.4
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| vaultcat-1.0.4.tar.gz | 459.8 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| vaultcat-1.0.4-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 910.3 kB
Release files / vaultcat-1.0.4.tar.gz
| Download URL | vaultcat-1.0.4.tar.gz |
|---|---|
| Size | 459.8 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
fe5f381431749f503c8fa5c7282d1b5180d1f339a07020da752266d898e1a815
|
|
BLAKE2b-256 checksum How to use checksums |
e7d1bcf8c574282d17f08ab32a89622f33af96351e431485ccba80ec9ce838ff
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/7.0.0 CPython/3.14.0
|
Release files / vaultcat-1.0.4-py3-none-any.whl
| Download URL | vaultcat-1.0.4-py3-none-any.whl |
|---|---|
| Size | 450.5 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
febb9653c2b6d997150c7cc92b6bb356d37d86de6ef8b3801e060a7f4675d66e
|
|
BLAKE2b-256 checksum How to use checksums |
d85646e08d7a6e4c256281bb07f6f9ce9f876ad5647302ff7d932225e182cc22
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/7.0.0 CPython/3.14.0
|