Credential Access
LaZagne
Local credential harvester.
credentialspost-exploitation
lazagne — terminal
$ lazagne.exe allWhat it does
LaZagne recovers passwords stored locally by browsers, mail clients, databases, and the OS. It's common in post-exploitation to pivot using already-stored credentials.
Common use cases
- •Extract saved browser passwords from a compromised workstation for lateral movement.
- •Recover database client and mail client credentials stored on a local machine.
- •Collect WiFi passwords and network-share credentials from a Windows host post-exploitation.
Key features
- •Retrieves passwords from browsers, mail clients, databases, WiFi, and system vaults.
- •Supports Windows, Linux, and macOS desktop credential stores.
- •Runs in a single command to dump all supported applications at once.
- •Generates reports in JSON and plain text for easy integration into logs.
Source
https://github.com/AlessandroZ/LaZagne ↗More Credential Access tools
Need hosted scanning instead of local tooling?
Run a scan in the browser →