Test SSL Security Including Ciphers, Protocols & Detect Flaws
ID: 63d7ac96-ab3d-5e08-8523-ab433676d36e
STIX ID: report--63d7ac96-ab3d-5e08-8523-ab433676d36e
Feed Name: Darknet
DumpBrowserSecrets is a publicly available post-exploitation tool designed to harvest browser-stored credentials and session tokens from major Windows browsers (Chrome, Edge, Brave, Opera family, Vivaldi, and Firefox). It bypasses App-Bound Encryption in Chromium-based browsers by spawning a headless Chromium process, injecting a DLL via Early Bird APC to call the IElevator COM interface, and then decrypts on-disk SQLite and JSON stores (DPAPI/NSS handling for other browsers), outputting structured JSON while employing runtime evasion techniques to reduce EDR detection—making it a high-risk capability for credential theft and cloud account takeover in assumed-breach scenarios.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
