The LaZagne project is an open source application used to retrieve lots of passwords stored on a local computer. Each software stores its passwords using different techniques (plaintext, APIs, custom algorithms, databases, etc.). This tool has been developed for the purpose of finding these passwords for the most commonly-used software. This project has been added to pupy as a post-exploitation module. Python code will be interpreted in memory without touching the disk and it works on Windows and Linux host. Standalones are now available here: https://github.com/AlessandroZ/LaZagne/releases/ Installation: pip install -r requirements.txt Usage: - Launch all modules: laZagne.exe all - Launch only a specific module: laZagne.exe browsers - Launch only a specific software script: laZagne.exe browsers -firefox - Write all passwords found into a file (-oN for Normal txt, -oJ for Json, -oA for All). Note: If you have problems to parse JSON results written as multi-line strings, check this. - Get help: laZagne.exe -h - Change verbosity mode (2 different levels): laZag
FEATURES
EXPLORE BY TAGS
SIMILAR TOOLS
Interactive online malware sandbox for real-time analysis and threat intelligence
A digital archive of the internet, allowing users to capture and browse archived web pages.
SharpEDRChecker scans system components to detect security products and tools.
A suite of tools for Wi-Fi network security assessment and penetration testing.
Explore the top million websites, ranked by referring subnets, and gain insights into online influence and popularity.
A collection of Python scripts for password spraying attacks against Lync/S4B & OWA, featuring Atomizer, Vaporizer, Aerosol, and Spindrift tools.
Tool for enumerating proxy configurations and generating CobaltStrike-compatible shellcode.
An Azure Function that validates and relays Cobalt Strike beacon traffic based on Malleable C2 profile authentication.
AHHHZURE is an automated deployment script that creates vulnerable Azure cloud lab environments for offensive security training and cloud penetration testing practice.