vaultcat is an open-source toolkit for full-lifecycle penetration testing of HashiCorp Vault. It supports reconnaissance, credential hijacking, privilege escalation, data exfiltration, pivoting, and persistence. The tool operates across CLI, AI-assisted chat, and MCP server modes, making it suitable for security professionals and red teamers conducting Vault security assessments.
In the Developer Tools space, vaultcat takes a focused approach. It focuses on performing comprehensive penetration testing and red team operations against HashiCorp Vault instances. vaultcat is an open-source project aimed at security researchers. The project is open source (MIT). vaultcat is available on the command line and API, and it can be self-hosted.
Muhammed Kurtoglu builds and maintains vaultcat, and it first shipped in 2026. The project is developed in the open on GitHub with 82 commits in the last 90 days. Among its 5 catalogued features are Vault Reconnaissance, Privilege Escalation, and Credential Exfiltration. It exposes integrations via an MCP server and a public API.
Summary written by a language model from the project’s public pages.
What PulseGate has recorded for this listing
Same category — not a similarity match