Web Application Log Forensics After a Hack
ID: f757c9da-def5-573b-83e8-05fa80e19260
STIX ID: report--f757c9da-def5-573b-83e8-05fa80e19260
Feed Name: Darknet
**DumpBrowserSecrets** is a public post-exploitation tool that harvests browser-stored credentials (passwords, session cookies, OAuth refresh tokens, credit cards, autofill data, history, bookmarks) from Chromium-based browsers (including App-Bound Encryption bypass via IElevator) and Firefox, using DLL injection, headless Chromium spawning, and multiple evasion techniques; it enables rapid session and account takeover on compromised Windows developer hosts and is useful both for red teams and malicious actors.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
