Free Command Line Packet/Network Sniffer For Windows (Raw Sockets)
ID: dab3dc53-d44e-5931-a865-0e5eea985d8e
STIX ID: report--dab3dc53-d44e-5931-a865-0e5eea985d8e
Feed Name: Darknet
DumpBrowserSecrets is a publicly available Windows post-exploitation tool (executable + DLL) that harvests browser-stored credentials and session artifacts across Chrome/Edge/Brave (App‑Bound Encryption bypass), Opera/Opera GX/Vivaldi (DPAPI), and Firefox (NSS). It achieves App‑Bound Encryption decryption by spawning a headless Chromium process, injecting a DLL via Early Bird APC to call the IElevator COM interface, and then locally decrypts browser SQLite/JSON stores; the tool includes evasion measures (string obfuscation, API hashing, PPID/argument spoofing, handle duplication) and outputs structured JSON for red-team use, but also represents a realistic risk for lateral movement and cloud account takeover on compromised developer endpoints.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
