BloodHound – Hacking Active Directory Trust Relationships
ID: a8d24afb-2c6d-5a6f-9334-c470202bb06d
STIX ID: report--a8d24afb-2c6d-5a6f-9334-c470202bb06d
Feed Name: Darknet
DumpBrowserSecrets is a post-exploitation Windows tool (binary + DLL) that harvests credentials and session tokens from major Chromium- and Gecko-based browsers by bypassing App-Bound Encryption (via spawning a headless Chromium process and using IElevator COM with early-bird APC DLL injection), retrieving DPAPI keys for some browsers, and handling Firefox NSS decryption. It outputs structured JSON, includes multiple EDR-evasion features (string obfuscation, API hashing, PPID/argument spoofing, file-handle duplication, custom SQLite parser), and is presented as a red-team utility for assessing credential exposure and endpoint controls.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
