A tool for parsing and decrypting MS-CHAPv2 network handshakes.
ID: fe0dc51e-918b-5c5f-83d3-b0314d0d10ff
STIX ID: report--fe0dc51e-918b-5c5f-83d3-b0314d0d10ff
Feed Name: Darknet
DumpBrowserSecrets is a post-exploitation credential-harvesting tool that extracts saved credentials, session cookies, OAuth refresh tokens, credit card data, autofill entries, and browsing history from major browsers (Chrome/Edge/Brave via App-Bound Encryption bypass, Opera/Vivaldi via DPAPI, and Firefox via NSS). The tool uses headless Chromium with Early Bird APC DLL injection and the IElevator COM interface to decrypt app-bound keys, includes operational evasion (string obfuscation, API hashing, PPID/argument spoofing, handle duplication, custom SQLite parser), and outputs structured JSON for red team use; the repo describes usage, an attack scenario, and detection/mitigation guidance.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
