What the attacker wants
The vault attacker wants a dump that converts into lasting callers. Empty the password manager, the API-key store, the HSM export, or the agent secret file, then use those strings from anywhere until rotation catches up. The conversion is steal-and-reuse: the tray that was meant to protect secrets becomes the tray that prints authority for the adversary. Vault pages are where buyers usually start, because dumps are familiar and expensive in ambient estates.
