Pass-The-Hash Toolkit v1.1 Available for Download
ID: 7eb41afa-fd29-510c-98e3-c5e0f600aa9b
STIX ID: report--7eb41afa-fd29-510c-98e3-c5e0f600aa9b
Feed Name: Darknet
DumpBrowserSecrets is a publicly documented post-exploitation tool that harvests credentials and session material from major Windows browsers (Chrome, Edge, Brave, Opera family, Vivaldi, Firefox) by using a headless Chromium process with Early Bird APC DLL injection to bypass App-Bound Encryption (IElevator COM), retrieving DPAPI/NSS secrets where applicable, and outputting structured JSON. The report describes its capabilities, evasion techniques (string obfuscation, API hashing, PPID/argument spoofing, handle duplication), typical attack scenarios and impacts (cloud account takeover, lateral movement), and detection/mitigation guidance for defenders.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
