PowerShell Runspace Post Exploitation Toolkit
ID: b558eb43-a4d3-51c4-b806-ca227922a71f
STIX ID: report--b558eb43-a4d3-51c4-b806-ca227922a71f
Feed Name: Darknet
DumpBrowserSecrets is a publicly documented post-exploitation credential-harvesting tool that targets browser-stored secrets across Chrome/Edge/Brave (App-Bound Encryption bypass via IElevator injection), Opera/ Vivaldi (DPAPI), and Firefox (NSS). It spawns headless browser processes and injects a DLL to decrypt app-bound keys, parses on-disk SQLite/JSON stores, and outputs structured JSON of cookies, logins, OAuth tokens, credit cards, and autofill data; the report also covers evasion techniques, usage examples, detection opportunities, and mitigation recommendations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
