logo

GKE Auditor – Detect Google Kubernetes Engine Misconfigurations

ID: 5435f226-d4d7-5275-abe5-0ad82377394d

STIX ID: report--5435f226-d4d7-5275-abe5-0ad82377394d

Feed Name: Darknet

Threat Score
75/100

Date Published: 2021-01-01

Date Updated: 2026-05-08

...
...

DumpBrowserSecrets is a publicly available post‑exploitation tool that harvests saved passwords, session cookies, OAuth refresh tokens, credit card numbers, autofill data, and browsing history from Chromium-based browsers (Chrome, Edge, Brave, Opera variants, Vivaldi) and Firefox on Windows. It bypasses Chrome's App‑Bound Encryption by spawning a headless Chromium instance and injecting a DLL via Early Bird APC to use the IElevator COM interface, includes evasion features (string obfuscation, API hashing, PPID/argument spoofing, handle duplication), outputs structured JSON, and is positioned for red team use while remaining relevant for defenders as a test of endpoint protections.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.