Microsoft SQL Server (MS-SQL) SQL Injection Vulnerability Tool
ID: 791e99ee-dddb-54c2-8def-b1f267735cf5
STIX ID: report--791e99ee-dddb-54c2-8def-b1f267735cf5
Feed Name: Darknet
**DumpBrowserSecrets** is a post‑exploitation browser credential‑harvesting tool that targets Chromium‑based and Gecko-based browsers, bypassing Chrome's App‑Bound Encryption by injecting a DLL into a spawned headless Chromium process to leverage the IElevator COM interface; it also handles DPAPI and NSS protected stores and writes extracted secrets as structured JSON. The report covers supported browsers, extracted data types (cookies, logins, OAuth tokens, credit cards, autofill, history), evasion techniques (string obfuscation, API hashing, PPID/argument spoofing, Early Bird APC injection, custom SQLite parser), attack scenarios, and detection/mitigation guidance.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
