Microsoft Data Harvesting Backported To Windows 7 & 8
ID: bb3b4926-74df-5801-86d0-b93a372615f4
STIX ID: report--bb3b4926-74df-5801-86d0-b93a372615f4
Feed Name: Darknet
DumpBrowserSecrets is a precompiled Windows post‑exploitation tool that harvests browser‑stored credentials (saved logins, session cookies, OAuth refresh tokens, credit cards, autofill data, and history) from Chromium‑based browsers and Firefox by bypassing App‑Bound Encryption (via spawning a headless browser and DLL injection using Early Bird APC to call the IElevator COM interface) or by extracting DPAPI/NSS keys; the report documents its capabilities, evasion techniques, usage, detection opportunities, and mitigation advice for red teams and defenders.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
