Vulnerability Scanning Plugin For Burp Proxy
ID: c9c8f700-12d0-5133-8a34-88fc9c3709ac
STIX ID: report--c9c8f700-12d0-5133-8a34-88fc9c3709ac
Feed Name: Darknet
DumpBrowserSecrets is a post‑exploitation credential‑harvesting tool that extracts saved credentials, session cookies, OAuth refresh tokens, credit card data, autofill, and history from Chromium‑based and Firefox browsers on Windows. It implements an App‑Bound Encryption bypass for Chrome/Edge/Brave by spawning a headless Chromium process and injecting a DLL to call the IElevator COM interface (using Early Bird APC injection), handles DPAPI for Opera/Vivaldi, and uses NSS decryption for Firefox; output is structured JSON and the tool includes evasion techniques aimed at EDRs. The report assesses detection opportunities, attack scenarios (cloud account takeover, lateral movement), red‑team relevance, and mitigation recommendations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
