logo

Manual Static Analysis Tool To Find Bugs

ID: 7fd269c2-b76f-5721-89c5-9e7390a08e08

STIX ID: report--7fd269c2-b76f-5721-89c5-9e7390a08e08

Feed Name: Darknet

Threat Score
75/100

Date Published: 2019-07-11

Date Updated: 2026-05-08

...
...

DumpBrowserSecrets is a publicly documented post‑exploitation tool that extracts credentials and session material from major Windows browsers (Chrome/Edge/Brave via App‑Bound Encryption bypass, Opera/Vivaldi via DPAPI, and Firefox via NSS decryption). The tool injects a DLL into a headless Chromium process to use the IElevator COM interface to decrypt app_bound_encrypted_key, parses browser SQLite/JSON stores, and outputs structured JSON; it includes evasion features (string obfuscation, API hashing, PPID/argument spoofing, handle duplication). The report covers usage, attack scenarios (fast lateral/cloud account takeover from a compromised developer host), detection opportunities and mitigation recommendations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.