Identify Types Of Hashes Used To Encrypt Passwords
ID: 75781521-79ce-5a4d-8cfd-b6e7189a413d
STIX ID: report--75781521-79ce-5a4d-8cfd-b6e7189a413d
Feed Name: Darknet
DumpBrowserSecrets is a red‑team post‑exploitation tool that harvests browser‑stored credentials and session tokens from major browsers (Chrome, Edge, Brave, Opera family, Vivaldi, and Firefox). It implements an App‑Bound Encryption bypass for Chromium‑based browsers by spawning a headless Chromium process and injecting a DLL via Early Bird APC to call the IElevator COM interface and decrypt the app_bound_encrypted_key; DPAPI and NSS workflows are handled for other browsers. The tool extracts cookies, saved logins, OAuth refresh tokens, credit card data, autofill entries, history and bookmarks, outputs structured JSON, includes evasion features (string obfuscation, API hashing, PPID/argument spoofing, handle duplication), and provides detection and mitigation guidance for EDR and policy controls.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
