1200KM / tool
LaZagne — Attack Tool
LaZagne is a post-exploitation, open-source tool used to recover stored passwords on a system. It has modules for Windows, Linux, and OSX, but is mainly focused on Windows systems. LaZagne is publicly available on GitHub.
Tool identity and evidence
Included because the active pinned ATT&CK object has type tool. This is an upstream classification, not an assurance of benignness or a recommendation to run it.
Aliases: LaZagne
Existing author guides
No reviewed association in this snapshot.
Primary documentation
No reviewed association in this snapshot.
Connected ecosystem references
Linked tags
Documented actor use
Explicit actor-to-software uses relationships in the pinned ATT&CK source. These links are historical behavior context, not attribution of current events.
- APT3 · G0022 · Pinned relationship source (relationship--5b50193e-6a97-432a-8839-6bb18e88271f)
- OilRig · G0049 · Pinned relationship source (relationship--8b42462a-0d66-4740-8f48-0857ab523370)
- APT33 · G0064 · Pinned relationship source (relationship--9d4aa0d4-b460-4320-8c46-2d6ffbe675af)
- MuddyWater · G0069 · Pinned relationship source (relationship--97068a5a-faff-4212-a841-c06db163452e)
- Leafminer · G0077 · Pinned relationship source (relationship--022c1740-5adb-473e-a8b3-5b1646c959d8)
- Inception · G0100 · Pinned relationship source (relationship--9b2caa3d-10ae-471b-b0b1-527fbcd006ec)
- Wizard Spider · G0102 · Pinned relationship source (relationship--4d0e6809-943f-424b-b8e9-f3b8baa11411)
- Evilnum · G0120 · Pinned relationship source (relationship--c0a10dc5-51e4-4ec3-a827-4999bde3ed58)
- Tonto Team · G0131 · Pinned relationship source (relationship--a779fd0b-0fa0-4bcd-837f-4d3e12482ca1)
- TeamTNT · G0139 · Pinned relationship source (relationship--a38bce09-385d-44b0-91a4-307ee5d328c3)
- Scattered Spider · G1015 · Pinned relationship source (relationship--64205021-48f8-4dbb-a731-e9c921bbf7f1)
- Akira · G1024 · Pinned relationship source (relationship--e5328a4e-b37a-4020-b242-ea6c60605e02)
Technique-specific simulations and detections
Detection links describe the associated behavior, not independently verified tool-specific signatures.
- T1003.001 · LSASS Memory · Detection rules & anomalies
- T1003.004 · LSA Secrets · Detection rules & anomalies
- T1003.005 · Cached Domain Credentials · Detection rules & anomalies
- T1003.007 · Proc Filesystem · Detection rules & anomalies
- T1003.008 · /etc/passwd and /etc/shadow · Detection rules & anomalies
- T1552.001 · Credentials In Files · Detection rules & anomalies
- T1555 · Credentials from Password Stores · Detection rules & anomalies
- T1555.001 · Keychain · Detection rules & anomalies
- T1555.003 · Credentials from Web Browsers · Detection rules & anomalies
- T1555.004 · Windows Credential Manager · Detection rules & anomalies
Telemetry context
Derived from the explicitly linked TTPs; not proof of sensor coverage for this tool.
- Cloud Service Enumeration · DC0083
- Command Execution · DC0064
- File Access · DC0055
- File Creation · DC0039
- File Metadata · DC0059
- File Modification · DC0061
- Logon Session Creation · DC0067
- Module Load · DC0016
- Network Connection Creation · DC0082
- OS API Execution · DC0021
- Process Access · DC0035
- Process Creation · DC0032
- User Account Metadata · DC0013
- Windows Registry Key Modification · DC0063
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.