Wazuh – Open Source Security Platform for Threat Detection, Visibility & Compliance
ID: dfce6c2f-30eb-5ee1-9fb6-3daf197ef015
STIX ID: report--dfce6c2f-30eb-5ee1-9fb6-3daf197ef015
Feed Name: Darknet
DumpBrowserSecrets is a public post-exploitation tool that harvests browser-stored credentials and session artifacts across Chromium- and Gecko-based browsers on Windows. It implements an App‑Bound Encryption bypass for modern Chromium builds by spawning a headless browser and injecting a DLL via Early Bird APC to call the IElevator COM interface, plus DPAPI and NSS handling for other browsers; outputs structured JSON and includes evasion techniques making it relevant for red teams and threat actors testing or abusing browser credential surfaces.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
