Application Protocol Detection & Fingerprinting
ID: 2c9143f9-4b01-5c04-b0f5-e003eec8f225
STIX ID: report--2c9143f9-4b01-5c04-b0f5-e003eec8f225
Feed Name: Darknet
Threat Score
**DumpBrowserSecrets** is a public post-exploitation tool that harvests browser-stored credentials and session tokens across Chromium-based and Firefox browsers by using techniques such as Early Bird APC DLL injection into a headless Chromium process and leveraging the IElevator COM interface to bypass App-Bound Encryption; it outputs structured JSON of extracted secrets and includes multiple evasion features to hamper detection.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
