logo

Best EDR Of The Market (BEOTM) – Endpoint Detection and Response Testing Tool

ID: bf7671e4-4226-5651-8e0f-a40472e45729

STIX ID: report--bf7671e4-4226-5651-8e0f-a40472e45729

Feed Name: Darknet

Threat Score
70/100

Date Published: 2024-01-04

Date Updated: 2026-05-08

...
...

DumpBrowserSecrets is a Windows post‑exploitation credential‑harvesting tool that extracts saved passwords, session cookies, OAuth tokens, credit card data, autofill entries, and history from major browsers (Chrome, Edge, Brave, Opera variants, Vivaldi, Firefox). It implements an App‑Bound Encryption bypass for Chromium (injecting a DLL into a headless Chromium process to call the IElevator COM interface), handles DPAPI and NSS decryption for other browsers, writes structured JSON output, and includes evasion techniques (string obfuscation, API hashing, PPID/argument spoofing, handle duplication). The report covers usage, an attack scenario demonstrating rapid credential extraction for lateral movement and cloud account takeover, detection opportunities (process injection, IElevator usage, headless browser instantiation, unusual reads of browser SQLite files), and mitigations such as using external credential managers and EDR rules that monitor IElevator and browser process behavior.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.