Web Application Vulnerability Scanner Evaluation Project
ID: 5b6d7d10-b695-556c-9934-c8f1b0c8c2b0
STIX ID: report--5b6d7d10-b695-556c-9934-c8f1b0c8c2b0
Feed Name: Darknet
DumpBrowserSecrets is a precompiled Windows post‑exploitation tool that extracts browser-stored credentials (passwords, cookies, OAuth tokens, credit cards, autofill and history) from major browsers by decrypting App‑Bound Encryption or DPAPI/NSS-protected stores. It performs a headless Chromium spawn with Early Bird APC DLL injection to use the IElevator COM interface for key decryption (Chromium), directly handles DPAPI for some browsers and NSS for Firefox, includes evasive features (string obfuscation, API hashing, PPID/argument spoofing, handle duplication, custom SQLite parser), outputs structured JSON, and is positioned for red-team assumed-breach testing while also being usable by malicious actors.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
