VulnScanners Logo

Credential Access

LaZagne

Local credential harvester.

credentialspost-exploitation
lazagne — terminal
$ lazagne.exe all

What it does

LaZagne recovers passwords stored locally by browsers, mail clients, databases, and the OS. It's common in post-exploitation to pivot using already-stored credentials.

Common use cases

  • Extract saved browser passwords from a compromised workstation for lateral movement.
  • Recover database client and mail client credentials stored on a local machine.
  • Collect WiFi passwords and network-share credentials from a Windows host post-exploitation.

Key features

  • Retrieves passwords from browsers, mail clients, databases, WiFi, and system vaults.
  • Supports Windows, Linux, and macOS desktop credential stores.
  • Runs in a single command to dump all supported applications at once.
  • Generates reports in JSON and plain text for easy integration into logs.

Source

https://github.com/AlessandroZ/LaZagne

More Credential Access tools

Need hosted scanning instead of local tooling?

Run a scan in the browser →