Mobile Forensics, Malware Analysis, and App Security Testing LiveCD
ID: c8136215-c135-52b1-926e-7f1988f925ff
STIX ID: report--c8136215-c135-52b1-926e-7f1988f925ff
Feed Name: Darknet
DumpBrowserSecrets is a post‑exploitation credential‑harvesting tool for Windows that extracts browser‑stored secrets (passwords, cookies, OAuth tokens, credit cards, autofill, history) from major Chromium‑based browsers and Firefox. It bypasses Chrome's App‑Bound Encryption by injecting a DLL into a headless Chromium process to call the IElevator COM interface, includes DPAPI and NSS handling for other browsers, and implements several evasion techniques; the report covers usage, attack scenarios, detection opportunities, and mitigation recommendations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
