Want Some COFEE? Microsoft Computer Online Forensic Evidence Extractor
ID: 3eb8df57-29e3-5406-adbd-6514d789b636
STIX ID: report--3eb8df57-29e3-5406-adbd-6514d789b636
Feed Name: Darknet
DumpBrowserSecrets is a publicly available post-exploitation tool that harvests browser-stored credentials (saved logins, session cookies, OAuth refresh tokens, credit cards, autofill and history) from major Chromium-based browsers and Firefox on Windows by bypassing App-Bound Encryption and DPAPI. The tool uses a headless Chromium process with Early Bird APC DLL injection to leverage the IElevator COM interface for key decryption, includes multiple operational evasion techniques, outputs structured JSON for red team use, and poses a high-risk credential-exposure vector for compromised developer or user endpoints; the report also outlines detection opportunities and mitigations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
