Academic Papers on Web Application Security
ID: 98cd6712-94eb-5284-a9d2-f72da7a541d3
STIX ID: report--98cd6712-94eb-5284-a9d2-f72da7a541d3
Feed Name: Darknet
DumpBrowserSecrets is a publicly documented post-exploitation tool that harvests browser-stored credentials and session tokens from major Windows browsers (Chrome/Edge/Brave via App‑Bound Encryption bypass, Opera/Vivaldi via DPAPI, Firefox via NSS). The tool injects a DLL into a headless Chromium process to decrypt app_bound_encrypted_key using the IElevator COM interface, parses on-disk SQLite/JSON stores, and outputs structured JSON; it includes operational evasion features and guidance on detection and mitigation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
