Graphical Interface (GUI) for Nmap on Windows
ID: c095890e-a890-5cdb-809b-4fe99fd26bd7
STIX ID: report--c095890e-a890-5cdb-809b-4fe99fd26bd7
Feed Name: Darknet
DumpBrowserSecrets is a publicly available post-exploitation tool that extracts browser-stored credentials (saved passwords, session cookies, OAuth refresh tokens, credit cards, autofill data, history, bookmarks) from Chromium-based browsers (Chrome, Edge, Brave, Opera variants, Vivaldi) and Firefox. It bypasses Chrome's App-Bound Encryption by spawning a headless Chromium process and injecting a DLL via Early Bird APC to call the IElevator COM interface, returns decrypted keys to the executable, parses on-disk SQLite/JSON stores, and outputs structured JSON. The report covers operational details, evasion techniques (string obfuscation, API hashing, PPID/argument spoofing, handle duplication, custom SQLite parser), example attack scenarios, detection opportunities, and mitigation advice.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
