Dough No! Revisiting Cookie Theft
ID: 76843586-ac43-5001-9ad8-0d9154e70aef
STIX ID: report--76843586-ac43-5001-9ad8-0d9154e70aef
Feed Name: SpecterOps Blog
This report explains Chrome and Edge’s shift to App-Bound encryption for cookie protection and details four practical techniques adversaries can still use to steal cookies: leveraging the DecryptData COM interface, reproducing SYSTEM-bound decryption (including Chrome-specific PostProcessData flows on domain-joined and non-domain hosts), enabling remote debugging to extract cookies via DevTools, and loading custom extensions to harvest cookies. It offers accompanying detections such as DPAPI debug event auditing, Sysmon CreateRemoteThread and ProcessAccessed monitoring, process creation flag detection for remote-debugging and load-extension switches, and extension ID auditing, while providing tooling references (e.g., Cookie-Monster and helper scripts) for red and blue teams.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
