Baike.dev
All toolsAI codingTrendingOpen sourceNewsSubmit
Log in
< Back to tools
D

DumpBrowserSecrets

> 编程语言
Open source

Extracts browser-stored data such as refresh tokens, cookies, saved credentials, credit cards, autofill entries, browsing history, and bookmarks from modern Chr

794 stars0 likes0 views
WebsiteGitHub

About

Extracts browser-stored data such as refresh tokens, cookies, saved credentials, credit cards, autofill entries, browsing history, and bookmarks from modern Chr

DumpBrowserSecrets

Extracts browser-stored data such as refresh tokens, cookies, saved credentials, credit cards, autofill entries, browsing history, and bookmarks from modern Chromium-based and Gecko-based browsers (Chrome, Microsoft Edge, Firefox, Opera, Opera GX, and Vivaldi).

Quick Links

Maldev Academy Home

Maldev Database

Malware Development Course Syllabus

Offensive Phishing Operations Course Syllabus

Ransomware Internals, Simulation and Detection Course Syllabus

How Does It Work

This project is an improved version of DumpChromeSecrets, and similarly consists of two components:

  1. Executable (DumpBrowserSecrets.exe)

Creates a headless Chromium process, injects the DLL via Early Bird APC injection, and receives extracted decryption keys. These keys are either App-Bound (extracted from Chrome, Brave, and Microsoft Edge) or DPAPI keys (used by Opera, Opera GX, and Vivaldi). Once the required keys have been recovered, this executable parses the browser's SQLite databases and JSON files on disk and decrypts the stored data, including credentials, cookies, tokens, and other browsing data. Additionally, when targeting non-Chromium-based browsers (e.g., Firefox), DumpBrowserSecrets.exe handles all the required steps for data extraction and decryption (without DLL-Injection).

  1. DLL (DllExtractChromiumSecrets.dll)

Runs inside Chromium browsers to decrypt the App-Bound encryption key using the IElevator COM interface. It leverages the IElevator COM interface to decrypt the App-Bound encryption key and retrieves the decrypted values of app_bound_encrypted_key and encrypted_key from the targeted browser's Local State file. These values are then returned to the executable, which performs all extraction operations.

[!NOTE] Unlike the DumpChromeSecrets project, this implementation performs all browser data extraction in the DumpBrowserSecrets.exe executable, while the DLL is limited to retrieving encryption keys from Chromium-based browsers.

Features

Below are some of the most notable features provided:

  • Compile-time string obfuscation and API hashing to evade static analysis.
  • PPID & argument spoofing via NtCreateUserProcess with manual CSRSS registration.
  • Custom SQLite3 file format parser (SQLoot), replacing sqlite-amalgamation in > v1.1.1.
  • Handle duplication to bypass file locks held by running browsers.
  • Encrypted output packs for offline decryption using a user-defined signature.

Usage

…

Extracted Data

The tables below showcase the exact data locations, formats, and encryption models used by each supported browser.

Chrome (App-Bound)

Data Type Database Path Format Encryption
Cookies %LOCALAPPDATA%\Google\Chrome\User Data\Default\Network\Cookies SQLite V20
Logins %LOCALAPPDATA%\Google\Chrome\User Data\Default\Login Data SQLite V20
Credit Cards %LOCALAPPDATA%\Google\Chrome\User Data\Default\Web Data SQLite V20
Tokens %LOCALAPPDATA%\Google\Chrome\User Data\Default\Web Data SQLite V20
Autofill %LOCALAPPDATA%\Google\Chrome\User Data\Default\Web Data SQLite Unencrypted
History %LOCALAPPDATA%\Google\Chrome\User Data\Default\History SQLite Unencrypted
Bookmarks %LOCALAPPDATA%\Google\Chrome\User Data\Default\Bookmarks JSON Unencrypted

Edge (App-Bound)

Data Type Database Path Format Encryption
Cookies %LOCALAPPDATA%\Microsoft\Edge\User Data\Default\Network\Cookies SQLite V20
Logins %LOCALAPPDATA%\Microsoft\Edge\User Data\Default\Login Data SQLite V20
Credit Cards %LOCALAPPDATA%\Microsoft\Edge\User Data\Default\Web Data SQLite V20
Tokens %LOCALAPPDATA%\Microsoft\Edge\User Data\Default\Web Data SQLite X
Autofill %LOCALAPPDATA%\Microsoft\Edge\User Data\Default\Web Data SQLite Unencrypted
History %LOCALAPPDATA%\Microsoft\Edge\User Data\Default\History SQLite Unencrypted
Bookmarks %LOCALAPPDATA%\Microsoft\Edge\User Data\Default\Bookmarks JSON Unencrypted

Brave (App-Bound)

Data Type Database Path Format Encryption
Cookies %LOCALAPPDATA%\BraveSoftware\Brave-Browser\User Data\Default\Network\Cookies SQLite V20
Logins %LOCALAPPDATA%\BraveSoftware\Brave-Browser\User Data\Default\Login Data SQLite V20
Credit Cards %LOCALAPPDATA%\BraveSoftware\Brave-Browser\User Data\Default\Web Data SQLite V20
Tokens %LOCALAPPDATA%\BraveSoftware\Brave-Browser\User Data\Default\Web Data SQLite X
Autofill %LOCALAPPDATA%\BraveSoftware\Brave-Browser\User Data\Default\Web Data SQLite Unencrypted
History %LOCALAPPDATA%\BraveSoftware\Brave-Browser\User Data\Default\History SQLite Unencrypted
Bookmarks %LOCALAPPDATA%\BraveSoftware\Brave-Browser\User Data\Default\Bookmarks JSON Unencrypted

Opera (DPAPI)

Data Type Database Path Format Encryption
Cookies %APPDATA%\Opera Software\Opera Stable\Default\Network\Cookies SQLite V10
Logins %APPDATA%\Opera Software\Opera Stable\Default\Login Data SQLite V10
Credit Cards %APPDATA%\Opera Software\Opera Stable\Default\Web Data SQLite V10
Tokens %APPDATA%\Opera Software\Opera Stable\Default\Web Data SQLite V10 + Base64
Autofill %APPDATA%\Opera Software\Opera Stable\Default\Web Data SQLite Unencrypted
History %APPDATA%\Opera Software\Opera Stable\Default\History SQLite Unencrypted
Bookmarks %APPDATA%\Opera Software\Opera Stable\Default\Bookmarks JSON Unencrypted

Opera GX (DPAPI)

Data Type Database Path Format Encryption
Cookies %APPDATA%\Opera Software\Opera GX Stable\Default\Network\Cookies SQLite V10
Logins %APPDATA%\Opera Software\Opera GX Stable\Default\Login Data SQLite V10
Credit Cards %APPDATA%\Opera Software\Opera GX Stable\Default\Web Data SQLite V10
Tokens %APPDATA%\Opera Software\Opera GX Stable\Default\Web Data SQLite V10 + Base64
Autofill %APPDATA%\Opera Software\Opera GX Stable\Default\Web Data SQLite Unencrypted
History %APPDATA%\Opera Software\Opera GX Stable\Default\History SQLite Unencrypted
Bookmarks %APPDATA%\Opera Software\Opera GX Stable\Default\Bookmarks JSON Unencrypted

Vivaldi (DPAPI)

Data Type Database Path Format Encryption
Cookies %LOCALAPPDATA%\Vivaldi\User Data\Default\Network\Cookies SQLite V10
Logins %LOCALAPPDATA%\Vivaldi\User Data\Default\Login Data SQLite V10
Credit Cards %LOCALAPPDATA%\Vivaldi\User Data\Default\Web Data SQLite V10
Tokens %LOCALAPPDATA%\Vivaldi\User Data\Default\Web Data SQLite X
Autofill %LOCALAPPDATA%\Vivaldi\User Data\Default\Web Data SQLite Unencrypted
History %LOCALAPPDATA%\Vivaldi\User Data\Default\History SQLite Unencrypted
Bookmarks %LOCALAPPDATA%\Vivaldi\User Data\Default\Bookmarks JSON Unencrypted

Firefox (NSS)

Data Type File / Database Path Format Encryption
Cookies %APPDATA%\Mozilla\Firefox\Profiles\\cookies.sqlite SQLite Unencrypted
Logins %APPDATA%\Mozilla\Firefox\Profiles\\logins.json JSON AES‑256‑CBC or 3DES‑CBC
Tokens %APPDATA%\Mozilla\Firefox\Profiles\\signedInUser.json JSON Unencrypted
Autofill %APPDATA%\Mozilla\Firefox\Profiles\\formhistory.sqlite SQLite Unencrypted
History %APPDATA%\Mozilla\Firefox\Profiles\\places.sqlite SQLite Unencrypted
Bookmarks %APPDATA%\Mozilla\Firefox\Profiles\\places.sqlite SQLite Unencrypted

Credits

  • Manual CSRSS process registration implementation from NtCreateUserProcess-Post
  • Chrome IElevator COM interface research from snovvcrash's gist
  • Edge & Brave IElevator COM interface research from Chrome-App-Bound-Encryption-Decryption
  • luci4 for technical guidance
  • SQLite amalgamation from sqlite.org In <= v1.1.1

Demo

https://github.com/user-attachments/assets/4290d525-7d5f-4a65-8624-2f9fa752e186

Issues· 2 open

View all issuesOpen on GitHub

No open issues yet, or sync has not completed.

> Tags

Cchromecredential-harvestingfirefoxmsedge

No comments yet. Be the first to share.

> Details

PublishedAug 1, 2026
UpdatedSep 17, 2026
Category编程语言
PricingOpen source

> Related tools

T
TypeScript
JavaScript 的超集,为前端与全栈提供静态类型
P
Python
通用编程语言,广泛用于 Web、数据与 AI
G
Go
Google 推出的简洁高效系统语言