| Technique | Procedure example |
|---|---|
| T1003.001 LSASS Memory |
LaZagne can perform credential dumping from memory to obtain account and password information. |
| T1003.004 LSA Secrets |
LaZagne can perform credential dumping from LSA secrets to obtain account and password information. |
| T1003.005 Cached Domain Credentials |
LaZagne can perform credential dumping from MSCache to obtain account and password information. |
| T1003.007 Proc Filesystem |
LaZagne can use the `<PID>/maps` and `<PID>/mem` files to identify regex patterns to dump cleartext passwords from the browser's process memory. |
| T1003.008 /etc/passwd and /etc/shadow |
LaZagne can obtain credential information from /etc/shadow using the shadow.py module. |
| T1552.001 Credentials In Files |
LaZagne can obtain credentials from chats, databases, mail, and WiFi. |
| T1555 Credentials from Password Stores |
LaZagne can obtain credentials from databases, mail, and WiFi across multiple platforms. |
| T1555.001 Keychain |
LaZagne can obtain credentials from macOS Keychains. |
| T1555.003 Credentials from Web Browsers |
LaZagne can obtain credentials from web browsers such as Google Chrome, Internet Explorer, and Firefox. |
| T1555.004 Windows Credential Manager |
LaZagne can obtain credentials from Vault files. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.