The Web Application Security Auditing Toolbox
ID: b927890c-8205-5122-a65f-030a2ed55aa0
STIX ID: report--b927890c-8205-5122-a65f-030a2ed55aa0
Feed Name: Darknet
DumpBrowserSecrets is a post-exploitation credential-harvesting tool that extracts saved credentials, session cookies, OAuth refresh tokens, credit card data, autofill entries, and browsing history from Chrome, Edge, Brave, Opera variants, Vivaldi, and Firefox; it bypasses Chrome's App‑Bound Encryption by injecting a DLL into a headless Chromium process to use the IElevator COM interface, handles DPAPI and NSS decryption for other browsers, includes evasion techniques for EDRs, outputs structured JSON for red-team use, and includes detection and mitigation recommendations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
