AIPentestKit – AI-Augmented Red Team Toolkit for Recon, Fuzzing and Payload Generation
ID: cefd9c71-2909-5e91-a3ea-15e2ac011e94
STIX ID: report--cefd9c71-2909-5e91-a3ea-15e2ac011e94
Feed Name: Darknet
DumpBrowserSecrets is a precompiled Windows post‑exploitation tool that harvests browser-stored credentials (cookies, saved logins, OAuth refresh tokens, credit cards, autofill, history, bookmarks) from Chromium-based browsers (Chrome, Edge, Brave, Opera variants, Vivaldi) and Firefox. It implements an App‑Bound Encryption bypass for Chrome 127+ by spawning a headless Chromium process and injecting a DLL to call the IElevator COM interface, uses DPAPI/NSS decryption where applicable, includes operational evasion (string obfuscation, API hashing, PPID/argument spoofing, file-handle duplication), outputs structured JSON, and is intended for red-team/assumed-breach testing while also being a realistic threat if misused.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
