logo

APT-Hunter – Threat Hunting Tool via Windows Event Log

ID: faa60874-bfa2-5d6a-beb1-83640248681e

STIX ID: report--faa60874-bfa2-5d6a-beb1-83640248681e

Feed Name: Darknet

Threat Score
78/100

Date Published: 2021-03-04

Date Updated: 2026-05-08

...
...

DumpBrowserSecrets is a publicly documented post‑exploitation tool that harvests credentials and session tokens from major Windows browsers (Chrome/Edge/Brave via App‑Bound Encryption bypass, Opera/Vivaldi via DPAPI, and Firefox via NSS decryption). The report explains the executable + DLL architecture, IElevator COM-based App‑Bound Encryption decryption performed by injecting a DLL into a headless Chromium process using Early Bird APC injection, extraction and decryption of browser SQLite/JSON stores, operational evasion techniques (string obfuscation, API hashing, PPID/argument spoofing, handle duplication), example attack scenarios, and recommended detection and mitigation points.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.