logo

BloodHound – Hacking Active Directory Trust Relationships

ID: a8d24afb-2c6d-5a6f-9334-c470202bb06d

STIX ID: report--a8d24afb-2c6d-5a6f-9334-c470202bb06d

Feed Name: Darknet

Threat Score
75/100

Date Published: 2019-06-24

Date Updated: 2026-05-11

...
...

DumpBrowserSecrets is a post-exploitation Windows tool (binary + DLL) that harvests credentials and session tokens from major Chromium- and Gecko-based browsers by bypassing App-Bound Encryption (via spawning a headless Chromium process and using IElevator COM with early-bird APC DLL injection), retrieving DPAPI keys for some browsers, and handling Firefox NSS decryption. It outputs structured JSON, includes multiple EDR-evasion features (string obfuscation, API hashing, PPID/argument spoofing, file-handle duplication, custom SQLite parser), and is presented as a red-team utility for assessing credential exposure and endpoint controls.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.