logo

PowerShell Runspace Post Exploitation Toolkit

ID: b558eb43-a4d3-51c4-b806-ca227922a71f

STIX ID: report--b558eb43-a4d3-51c4-b806-ca227922a71f

Feed Name: Darknet

Threat Score
75/100

Date Published: 2017-01-13

Date Updated: 2026-05-08

...
...

DumpBrowserSecrets is a publicly documented post-exploitation credential-harvesting tool that targets browser-stored secrets across Chrome/Edge/Brave (App-Bound Encryption bypass via IElevator injection), Opera/ Vivaldi (DPAPI), and Firefox (NSS). It spawns headless browser processes and injects a DLL to decrypt app-bound keys, parses on-disk SQLite/JSON stores, and outputs structured JSON of cookies, logins, OAuth tokens, credit cards, and autofill data; the report also covers evasion techniques, usage examples, detection opportunities, and mitigation recommendations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.