Vulnerable Website For Learning & Security Tool Evaluation
ID: 69e13e63-1d3f-58eb-838e-acca070f60d3
STIX ID: report--69e13e63-1d3f-58eb-838e-acca070f60d3
Feed Name: Darknet
DumpBrowserSecrets is a Windows post‑exploitation tool that harvests browser-stored credentials and session tokens from Chrome, Edge, Brave, Opera (and variants), Vivaldi, and Firefox. It implements an App-Bound Encryption bypass for Chromium browsers by spawning a headless process and injecting a DLL to call the IElevator COM interface, extracts DPAPI and NSS-protected secrets where applicable, outputs structured JSON, and includes multiple evasion techniques to reduce EDR detection. The report covers supported data types, usage examples, an attack scenario demonstrating rapid credential extraction, and recommendations for detection and mitigation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
