ATT&CKReferencesGitHub LaZagne Dec 2018

GitHub LaZagne Dec 2018

Zanni, A. (n.d.). The LaZagne Project !!!. Retrieved December 14, 2018.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples10

TechniqueUsed byProcedure example
T1003.001
LSASS Memory
ToolLaZagne

LaZagne can perform credential dumping from memory to obtain account and password information.

T1003.004
LSA Secrets
ToolLaZagne

LaZagne can perform credential dumping from LSA secrets to obtain account and password information.

T1003.005
Cached Domain Credentials
ToolLaZagne

LaZagne can perform credential dumping from MSCache to obtain account and password information.

T1003.007
Proc Filesystem
ToolLaZagne

LaZagne can use the `<PID>/maps` and `<PID>/mem` files to identify regex patterns to dump cleartext passwords from the browser's process memory.

T1003.008
/etc/passwd and /etc/shadow
ToolLaZagne

LaZagne can obtain credential information from /etc/shadow using the shadow.py module.

T1552.001
Credentials In Files
ToolLaZagne

LaZagne can obtain credentials from chats, databases, mail, and WiFi.

T1555
Credentials from Password Stores
ToolLaZagne

LaZagne can obtain credentials from databases, mail, and WiFi across multiple platforms.

T1555.001
Keychain
ToolLaZagne

LaZagne can obtain credentials from macOS Keychains.

T1555.003
Credentials from Web Browsers
ToolLaZagne

LaZagne can obtain credentials from web browsers such as Google Chrome, Internet Explorer, and Firefox.

T1555.004
Windows Credential Manager
ToolLaZagne

LaZagne can obtain credentials from Vault files.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.