PsMapExec – PowerShell Command Mapping for Lateral Movement
ID: 9e1e0191-c91d-5fb9-9cbe-27033037d6cf
STIX ID: report--9e1e0191-c91d-5fb9-9cbe-27033037d6cf
Feed Name: Darknet
DumpBrowserSecrets is a post‑exploitation credential‑harvesting tool that extracts saved logins, session cookies, OAuth tokens, credit cards, autofill data and history from major Chromium‑based and Firefox browsers by bypassing App‑Bound Encryption (via DLL injection into a headless Chromium process and the IElevator COM interface) and handling DPAPI/NSS where applicable; the report details supported browsers, extracted data types, evasion techniques, an attack scenario, and recommended detection and mitigation approaches.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
