Security System Analyzer an OVAL Based Scanner
ID: 813aefad-6228-5b50-ade3-e6181d55392c
STIX ID: report--813aefad-6228-5b50-ade3-e6181d55392c
Feed Name: Darknet
DumpBrowserSecrets is a post‑exploitation credential‑harvesting tool designed to extract saved passwords, session cookies, OAuth refresh tokens, credit card data, autofill entries, and browsing history from major Chromium‑based and Firefox browsers on Windows. It uses a headless Chromium spawn plus Early Bird APC DLL injection and the IElevator COM interface to bypass Chrome's App‑Bound Encryption (Chrome 127+), handles DPAPI or NSS where appropriate, and includes evasion techniques (string obfuscation, API hashing, PPID/argument spoofing, handle duplication). The report describes usage, output (JSON), an attack scenario emphasizing rapid cloud/SaaS account access, detection opportunities, and mitigations such as using external credential managers and EDR monitoring of IElevator and unexpected headless browser processes.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
