Web Services Footprinting, Discovery, Enumeration, Scanning and Fuzzing tool
ID: 006393a4-d465-51c5-ada8-6b6c62718b0a
STIX ID: report--006393a4-d465-51c5-ada8-6b6c62718b0a
Feed Name: Darknet
DumpBrowserSecrets is a publicly available post‑exploitation tool that harvests browser‑stored credentials and tokens from Chrome/Edge/Brave (via an IElevator App‑Bound Encryption bypass using DLL injection), Opera/Vivaldi (DPAPI), and Firefox (NSS). It outputs structured JSON, includes evasion techniques (string obfuscation, API hashing, PPID/argument spoofing, handle duplication), and is intended for red team/assumed‑breach testing but presents a high‑impact credential theft capability that can enable cloud account takeover and lateral movement.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
