Hacking Tools, Hacker News & Cyber Security
ID: ac23f345-4a82-5d5b-b1d9-a7fa5460329d
STIX ID: report--ac23f345-4a82-5d5b-b1d9-a7fa5460329d
Feed Name: Darknet
DumpBrowserSecrets is a public post-exploitation tool for Windows that harvests browser-stored credentials and session tokens across Chromium-based (including Chrome, Edge, Brave) and Gecko-based (Firefox) browsers by spawning a headless browser, injecting a DLL to use the IElevator COM interface to decrypt App-Bound Encryption keys, and parsing browser databases; it also handles DPAPI and NSS models. The report details extracted data types (cookies, OAuth tokens, saved logins, credit cards, autofill, history), evasion techniques (Early Bird APC injection, PPID/argument spoofing, API hashing, custom SQLite parser), usage examples, detection opportunities, and mitigation recommendations for enterprise environments.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
