PentestGPT – AI-Powered Penetration Testing Assistant
ID: 7cbd2536-7988-54c4-8469-f52e50f3a1ce
STIX ID: report--7cbd2536-7988-54c4-8469-f52e50f3a1ce
Feed Name: Darknet
DumpBrowserSecrets is a publicly documented post-exploitation tool that extracts saved passwords, session cookies, OAuth refresh tokens, credit card data, autofill entries, and browsing history from major Windows browsers. It bypasses Chrome's App-Bound Encryption by spawning a headless Chromium process, performing Early Bird APC DLL injection to use the IElevator COM interface, and returns decrypted keys to decrypt on-disk SQLite/JSON stores; Opera-family browsers use DPAPI recovery and Firefox uses NSS decryption. The report covers operational evasion (string obfuscation, API hashing, PPID/argument spoofing, handle duplication), output and usage, a realistic attack scenario against authenticated developer workstations, and detection/mitigation guidance for EDR and policy controls.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
