VoIP Security Testing Tools List from VoIPSA
ID: ff321539-6647-5b48-b6af-039c2d5ccd67
STIX ID: report--ff321539-6647-5b48-b6af-039c2d5ccd67
Feed Name: Darknet
DumpBrowserSecrets is a publicly available post‑exploitation tool that harvests browser-stored credentials and session material from major Windows browsers (Chrome/Edge/Brave via an App‑Bound Encryption bypass using IElevator, Opera/Vivaldi via DPAPI, and Firefox via NSS decryption). It operates by spawning a headless Chromium process and injecting a DLL via Early Bird APC to decrypt app_bound_encrypted_key or by directly parsing and decrypting on-disk browser stores, outputs structured JSON, includes multiple evasion techniques (string obfuscation, API hashing, PPID/argument spoofing, handle duplication, custom SQLite parser), and the report includes detection and mitigation guidance for endpoint defenders.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
