Windows Process Execution: LaZagne Credential Dumping Utility (lazagne.exe)

Flags Windows process launches consistent with running LaZagne (lazagne.exe) for credential and password recovery.

FreeReviewedSigma · Medium · v2
Product
windows
Category
process_creation
Author
Nasreddine Bencherchali, Swachchhanda Shrawan Poudel (Nextron Systems) (SigmaHQ), DRL 1.1
Published
2024-06-24
Updated
2026-07-31

What it detects

This rule flags execution of the LaZagne utility on Windows, including common command-line module selections and options associated with credential collection. Attackers use LaZagne to extract passwords and other sensitive data from local systems, enabling follow-on account access and lateral movement. It relies on Windows process creation telemetry, matching process image names and command-line contents tied to LaZagne’s typical usage patterns.

Changelog

v2
  1. v2
    Candidate ingested via manual entry.2026-07-31
  2. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.