Handy Recovery for Recovering Deleted Data on Windows
ID: febe780d-3fc3-5bfb-88fe-2f1414b6af4c
STIX ID: report--febe780d-3fc3-5bfb-88fe-2f1414b6af4c
Feed Name: Darknet
DumpBrowserSecrets is a publicly documented post-exploitation tool that extracts a wide range of browser-stored secrets (saved credentials, cookies, OAuth refresh tokens, credit cards, autofill and history) from major Chromium-based and Gecko-based browsers on Windows. It implements an App-Bound Encryption bypass for Chrome/Edge/Brave by spawning a headless Chromium process and injecting a DLL via Early Bird APC to call the IElevator COM interface, handles DPAPI and NSS decryption for other browsers, and includes multiple operational evasion features; the tool outputs structured JSON and is intended for red team/assumed-breach use while also illustrating a realistic attacker path to SaaS/cloud account takeover and lateral movement.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
