Force Push Scanner – Hunt GitHub Dangling Commits for Leaked Secrets
ID: 744e7f7d-6d5a-5687-8609-62f8d54d6d0d
STIX ID: report--744e7f7d-6d5a-5687-8609-62f8d54d6d0d
Feed Name: Darknet
DumpBrowserSecrets is a publicly documented post-exploitation tool that harvests browser-stored credentials (passwords, session cookies, OAuth refresh tokens, credit cards, autofill data, and history) from major Chromium- and Gecko-based browsers on Windows. It implements an App-Bound Encryption bypass for Chrome/Edge/Brave via DLL injection into a headless Chromium process using Early Bird APC and the IElevator COM interface, handles DPAPI and NSS decryption for other browsers, includes multiple evasion techniques (string obfuscation, API hashing, PPID/argument spoofing, handle duplication), outputs structured JSON, and is positioned as a red-team tool useful for assessing credential exposure and endpoint defenses.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
