Microsoft Loves you to Pirate Their Software
ID: 35663c17-3290-5546-a87f-f85543f66113
STIX ID: report--35663c17-3290-5546-a87f-f85543f66113
Feed Name: Darknet
DumpBrowserSecrets is a Windows post‑exploitation tool that extracts saved credentials, session cookies, OAuth refresh tokens, credit card and autofill data, and browsing history from major Chromium‑based and Firefox browsers by bypassing App‑Bound Encryption (via spawning a headless Chromium process and using an injected DLL with the IElevator COM interface) or DPAPI/NSS mechanisms; it outputs structured JSON and includes evasion features (string obfuscation, API hashing, PPID/argument spoofing, handle duplication, custom SQLite parser). The report covers supported browsers, extracted artifact types, attack and red‑team usage scenarios, detection opportunities, mitigations, FAQs, and links to the project.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
