Web Application Vulnerability Scanning Framework
ID: 17f17ebd-5f5b-5f66-86a5-0c63d1a0acdb
STIX ID: report--17f17ebd-5f5b-5f66-86a5-0c63d1a0acdb
Feed Name: Darknet
DumpBrowserSecrets is a public post-exploitation tool that extracts credentials and session tokens from major Windows browsers (Chrome/Edge/Brave via App-Bound Encryption bypass, Opera/Vivaldi via DPAPI, and Firefox via NSS). It uses headless Chromium + Early Bird APC DLL injection to call the IElevator COM interface and retrieve encryption keys, outputs structured JSON, and includes multiple evasion techniques, making it a potent capability for lateral movement and cloud account takeover during assumed-breach exercises.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
