Enumerate All IP/Host Patterns In A Web Page
ID: 2f0ebd89-241b-563f-8bfe-d6637bc0149b
STIX ID: report--2f0ebd89-241b-563f-8bfe-d6637bc0149b
Feed Name: Darknet
DumpBrowserSecrets is a Windows post-exploitation tool that harvests browser-stored credentials and session tokens from Chrome, Edge, Brave, Opera variants, Vivaldi, and Firefox by using DLL injection into a headless Chromium process to bypass App-Bound Encryption (IElevator COM) and by extracting DPAPI/NSS-protected data; it outputs structured JSON for red-team use and includes operational evasion features (string obfuscation, API hashing, PPID/argument spoofing, handle duplication) that make detection and mitigation more challenging, enabling rapid account takeover and lateral movement if used maliciously.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
