Discover & Remove Alternate Data Streams (ADS)
ID: bff4d2e4-12e2-5cb5-86f8-4ae863caef32
STIX ID: report--bff4d2e4-12e2-5cb5-86f8-4ae863caef32
Feed Name: Darknet
DumpBrowserSecrets is a publicly documented post‑exploitation tool that extracts credentials and session material from major Windows browsers (Chrome/Edge/Brave via an App‑Bound Encryption bypass using IElevator and injected DLLs; Opera/Vivaldi via DPAPI keys; Firefox via NSS). The tool spawns headless browser processes, uses Early Bird APC DLL injection to retrieve decryption keys, parses SQLite/JSON stores, outputs structured JSON containing saved logins, cookies, OAuth tokens and more, and includes multiple evasion techniques intended to reduce EDR detection; the report describes attack scenarios, detection opportunities, and mitigation advice.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
