Hacking Tools, Hacker News & Cyber Security
ID: d242afcd-b88f-572f-82ba-eaf8a510a831
STIX ID: report--d242afcd-b88f-572f-82ba-eaf8a510a831
Feed Name: Darknet
DumpBrowserSecrets is a Windows post-exploitation tool that harvests browser-stored credentials and session tokens from major browsers (Chrome, Edge, Brave, Opera series, Vivaldi, and Firefox). It implements an App-Bound Encryption bypass for Chromium-based browsers by spawning a headless Chromium process and injecting a DLL via Early Bird APC to use the IElevator COM interface, retrieves DPAPI keys for certain browsers, and decrypts Firefox NSS-protected logins; outputs are written as structured JSON. The README documents usage, evasion techniques (string obfuscation, API hashing, PPID/argument spoofing, file-handle duplication), detection opportunities, and red-team relevance for assumed-breach engagements.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
