EyeWitness – A Rapid Web Application Triage Tool
ID: b4908414-9cd7-5e78-bbe6-07a5aef1c8cd
STIX ID: report--b4908414-9cd7-5e78-bbe6-07a5aef1c8cd
Feed Name: Darknet
DumpBrowserSecrets is a publicly available post‑exploitation tool that harvests browser-stored credentials and session data (passwords, cookies, OAuth refresh tokens, credit cards, autofill, history) from Chrome/Edge/Brave (App‑Bound Encryption), Opera/Vivaldi (DPAPI) and Firefox (NSS). The report details a Chrome 127+ App‑Bound Encryption bypass using a headless Chromium process with Early Bird APC DLL injection and the IElevator COM interface, describes evasion features (string obfuscation, API hashing, PPID/argument spoofing, handle duplication), provides usage examples and red-team context, and outlines detection and mitigation opportunities.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
