logo

Discover & Remove Alternate Data Streams (ADS)

ID: bff4d2e4-12e2-5cb5-86f8-4ae863caef32

STIX ID: report--bff4d2e4-12e2-5cb5-86f8-4ae863caef32

Feed Name: Darknet

Threat Score
75/100

Date Published: 2010-04-09

Date Updated: 2026-05-12

...
...

DumpBrowserSecrets is a publicly documented post‑exploitation tool that extracts credentials and session material from major Windows browsers (Chrome/Edge/Brave via an App‑Bound Encryption bypass using IElevator and injected DLLs; Opera/Vivaldi via DPAPI keys; Firefox via NSS). The tool spawns headless browser processes, uses Early Bird APC DLL injection to retrieve decryption keys, parses SQLite/JSON stores, outputs structured JSON containing saved logins, cookies, OAuth tokens and more, and includes multiple evasion techniques intended to reduce EDR detection; the report describes attack scenarios, detection opportunities, and mitigation advice.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.