Automated Web Application Security Reconnaissance Tool
ID: e946dd4c-a47b-5bc7-8a71-8b25a4a2ec35
STIX ID: report--e946dd4c-a47b-5bc7-8a71-8b25a4a2ec35
Feed Name: Darknet
DumpBrowserSecrets is a Windows post-exploitation tool that harvests browser-stored secrets (saved passwords, session cookies, OAuth refresh tokens, credit card data, autofill entries, history, and bookmarks) from major Chromium-based and Gecko-based browsers. It implements an App-Bound Encryption bypass for Chrome/Edge/Brave by launching a headless Chromium process and injecting a DLL to call the IElevator COM interface, uses DPAPI extraction for Opera-family browsers, and NSS decryption for Firefox; it includes evasion techniques (string obfuscation, API hashing, PPID/argument spoofing, handle duplication) and outputs structured JSON suitable for red team testing and assessing credential blast radius.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
