Second Order – Subdomain Takeover Scanner Tool
ID: 67fb14ab-acb8-5f12-8ebc-ee477e0b9380
STIX ID: report--67fb14ab-acb8-5f12-8ebc-ee477e0b9380
Feed Name: Darknet
DumpBrowserSecrets is a publicly documented post-exploitation tool that harvests browser-stored credentials and session tokens from Chrome, Edge, Brave (including an App‑Bound Encryption bypass), Opera-family browsers (DPAPI), and Firefox (NSS). The analysis describes how the tool injects a DLL into a headless Chromium process to use the IElevator COM interface to decrypt app_bound_encrypted_key, parses on-disk SQLite/JSON stores to extract high-value artifacts (saved logins, cookies, OAuth tokens, autofill, credit cards), and includes evasion techniques (string obfuscation, API hashing, PPID/argument spoofing, handle duplication) and detection/mitigation recommendations for defenders.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
