Linux Reverse Engineering Hacker Challenge
ID: 235f5e6e-7d01-5f8f-a15b-54adf3bc5592
STIX ID: report--235f5e6e-7d01-5f8f-a15b-54adf3bc5592
Feed Name: Darknet
DumpBrowserSecrets is a post-exploitation credential-harvesting tool that extracts saved credentials, session cookies, OAuth refresh tokens, credit card data, autofill entries, and browsing history from major Chromium-based and Firefox browsers on Windows by using techniques including Early Bird APC DLL injection into a headless Chromium process to leverage the IElevator COM interface (bypassing Chrome App‑Bound Encryption), DPAPI extraction for some browsers, and NSS decryption for Firefox; the report details implementation, evasion features, supported browsers, usage examples, red-team relevance, detection opportunities, and mitigation recommendations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
