LaZagne

S0349

Tool.View on attack.mitre.org

About this tool

LaZagne is a post-exploitation, open-source tool used to recover stored passwords on a system. It has modules for Windows, Linux, and OSX, but is mainly focused on Windows systems. LaZagne is publicly available on GitHub.

Techniques used10

Procedure examples10

TechniqueProcedure example
T1003.001
LSASS Memory

LaZagne can perform credential dumping from memory to obtain account and password information.

T1003.004
LSA Secrets

LaZagne can perform credential dumping from LSA secrets to obtain account and password information.

T1003.005
Cached Domain Credentials

LaZagne can perform credential dumping from MSCache to obtain account and password information.

T1003.007
Proc Filesystem

LaZagne can use the `<PID>/maps` and `<PID>/mem` files to identify regex patterns to dump cleartext passwords from the browser's process memory.

T1003.008
/etc/passwd and /etc/shadow

LaZagne can obtain credential information from /etc/shadow using the shadow.py module.

T1552.001
Credentials In Files

LaZagne can obtain credentials from chats, databases, mail, and WiFi.

T1555
Credentials from Password Stores

LaZagne can obtain credentials from databases, mail, and WiFi across multiple platforms.

T1555.001
Keychain

LaZagne can obtain credentials from macOS Keychains.

T1555.003
Credentials from Web Browsers

LaZagne can obtain credentials from web browsers such as Google Chrome, Internet Explorer, and Firefox.

T1555.004
Windows Credential Manager

LaZagne can obtain credentials from Vault files.

Groups that use it12

Campaigns0

None recorded.

References1

  1. GitHub LaZagne Dec 2018 Open source
    Zanni, A. (n.d.). The LaZagne Project !!!. Retrieved December 14, 2018.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.