Baike.dev
All toolsTrendingOpen sourceNewsSubmit
Log in
< 返回工具列表
H

HackBrowserData

> 编程语言
开源

Extract and decrypt browser data, supporting multiple data types, runnable on various operating systems (macOS, Windows, Linux).

14.4K stars0 点赞0 次浏览
访问官网GitHub

工具介绍

Extract and decrypt browser data, supporting multiple data types, runnable on various operating systems (macOS, Windows, Linux).

HackBrowserData

HackBrowserData is a command-line tool for decrypting and exporting browser data (passwords, history, cookies, bookmarks, credit cards, download history, localStorage, sessionStorage and extensions) from the browser. It supports the most popular Chromium-based browsers and Firefox on Windows, macOS and Linux, plus Safari on macOS.

It can also decrypt data across machines and operating systems: export the master keys on the origin host, then decrypt a copy of the data offline on any other host — even for a browser that the analyst host's OS cannot run (see Cross-host decryption).

Disclaimer: This tool is only intended for security research. Users are responsible for all legal and related liabilities resulting from the use of this tool. The original author does not assume any legal responsibility.

Supported Data Categories

Category Chromium-based Firefox Safari Password ✅ ✅ ✅ Cookie ✅ ✅ ✅ Bookmark ✅ ✅ ✅ History ✅ ✅ ✅ Download ✅ ✅ ✅ Credit Card ✅ - - Extension ✅ ✅ ✅ LocalStorage ✅ ✅ ✅ SessionStorage ✅ - -

Supported Browsers

On macOS, some Chromium-based browsers require a current user password to decrypt.

Password decryption may fail on macOS 26.4 or later.

Browser Windows macOS Linux Chrome ✅² ✅ ✅ Chrome Beta ✅² ✅ ✅ Chromium ✅ ✅ ✅ Edge ✅² ✅ ✅ Brave ✅² ✅ ✅ Opera ✅ ✅ ✅ OperaGX ✅ ✅ - Vivaldi ✅ ✅ ✅ Yandex ✅ ✅ - CocCoc ✅² ✅ - Arc ✅ ✅ - DuckDuckGo³ ✅ - - QQ³ ✅ - - 360 ChromeX³ ✅ - - 360 Chrome³ ✅ - - DC Browser³ ✅ - - Sogou Explorer³ ✅ - - Firefox ✅ ✅ ✅ Safari¹ - ✅ -

¹ Safari requires Full Disk Access; enable it in System Settings → Privacy & Security → Full Disk Access if extraction returns empty results.

² On Windows, decrypting Chromium 127+ cookies (Chrome / Chrome Beta / Edge / Brave / CocCoc) requires the App-Bound Encryption payload built via make build-windows — see Building from source below.

³ These browsers ship only on Windows, but their data is decryptable on any OS: pull the files with archive, export the keys with dumpkeys, then decrypt on macOS or Linux with restore — see Cross-host decryption.

Getting Started

Install

Installation of HackBrowserData is dead-simple, just download the release for your system and run the binary.

In some situations, this security tool will be treated as a virus by Windows Defender or other antivirus software and can not be executed. The code is all open source, you can modify and compile by yourself.

Building from source

Requires Go 1.20+.

git clone https://github.com/moonD4rk/HackBrowserData
cd HackBrowserData
go build ./cmd/hack-browser-data/

Cross-platform build

# For Windows (standard build, no Chromium 127+ ABE cookie support)
GOOS=windows GOARCH=amd64 go build ./cmd/hack-browser-data/

# For Linux
GOOS=linux GOARCH=amd64 go build ./cmd/hack-browser-data/

Windows build with App-Bound Encryption (optional)

Chrome / Chrome Beta / Edge / Brave / CocCoc 127+ protect cookies with App-Bound Encryption. Decrypting those cookies requires a small C payload — Zig (0.13+) is the recommended C toolchain (the Makefile calls zig cc). MinGW-w64 gcc can also build the sources manually if you bypass make payload.

# 1. Install Zig
brew install zig                 # macOS
scoop install zig                # Windows (scoop)
# or download from https://ziglang.org/download/

# 2. Build the payload (outputs crypto/windows/payload/abe_extractor_amd64.bin)
make payload

# 3. Build hack-browser-data.exe with the ABE payload embedded
make build-windows

The resulting hack-browser-data.exe includes full ABE cookie decryption on Chromium 127+.

Usage

…

dump - Extract and decrypt browser data (default)

Running hack-browser-data without a subcommand defaults to dump.

Flag Short Default Description --browser -b all Target browser (all|chrome|firefox|edge|...) --category -c all Data categories, comma-separated (all|password|cookie|bookmark|history|download|creditcard|extension|localstorage|sessionstorage) --format -f json Output format (csv|json|cookie-editor) --dir -d results Output directory --profile-path -p Custom profile dir path, get with chrome://version --keychain-pw macOS keychain password --zip false Compress output to zip

--format cookie-editor writes only cookies, as a JSON array matching the Cookie-Editor browser extension's import format; non-cookie categories are skipped.

Cross-host decryption

Decrypt browser data on an analyst host that was collected on a different origin host — including a browser whose engine the analyst's OS cannot even install (e.g. decrypt Sogou or QQ Browser data on macOS). Nothing platform-bound (DPAPI, macOS Keychain, Chrome App-Bound Encryption) has to leave the origin: the master keys are exported once, and decryption then runs entirely offline from a copy of the data.

The workflow uses three commands and two transportable artifacts:

Step Host Command Produces 1 origin dumpkeys keys.json — portable master keys 2 origin archive browser-data.zip — only the files needed to decrypt 3 analyst restore decrypted output (csv / json / cookie-editor)
# On the origin host (any OS) — export the keys and pack the data
hack-browser-data dumpkeys -o keys.json
hack-browser-data archive  -o browser-data.zip

# Copy keys.json + browser-data.zip to the analyst host, then decrypt offline
hack-browser-data restore --keys keys.json --data-zip browser-data.zip

keys.json contains plaintext master keys — treat it as a secret. dumpkeys -o writes it with 0600 permissions; prefer streaming it over a secure channel instead of leaving it on disk.

dumpkeys - Export master keys for cross-host decryption

Derives each Chromium installation's master keys on the origin host and writes them as JSON (Firefox / Safari have no portable key and are skipped). Defaults to stdout so it can be piped over SSH.

Flag Short Default Description --browser -b all Target browser (all|chrome|edge|...) --output -o stdout Output file (written 0600); stdout if omitted --keychain-pw macOS keychain password

archive - Pack decryption-relevant files for transport

Collects only the files a restore actually needs (cookies, login data, history, …) through the same locked-file bypass used for extraction, so live SQLite files are read safely on Windows. The zip is laid out as <browser-key>/<User Data layout>, so one archive can carry several browsers and restore stays unambiguous. Entry names are always forward-slash, so a Windows-produced archive restores on macOS / Linux.

Flag Short Default Description --browser -b all Target browser (all|chrome|edge|...) --category -c all Data categories, comma-separated --output -o browser-data.zip Output archive path

restore - Decrypt copied data with exported keys

Rebuilds each Chromium engine straight from keys.json and decrypts the supplied data — it never consults the analyst's local browser table, so the browsers you can restore are exactly the vaults in your keys.json. Supply the data one of two ways (exactly one is required):

  • --data-zip — a zip produced by archive; extracted to a temp dir and removed afterward.
  • --data-dir — a directory. Either the archive layout (<browser-key>/..., several browsers at once), or one browser's hand-copied User Data root, which is unambiguous only for a single browser — so pair it with -b.

-b is an optional filter over the dump's vaults, not a required selector.

Flag Short Default Description --keys required Keys file from dumpkeys (use - for stdin) --data-zip Zip from archive (mutually exclusive with --data-dir) --data-dir Copied data dir (mutually exclusive with --data-zip) --browser -b Restore only this browser; must match a vault in --keys --category -c all Data categories, comma-separated --format -f json Output format (csv|json|cookie-editor) --dir -d results Output directory --zip false Compress output to zip

Cross-host examples

# Stream keys over SSH (no keys.json on disk), data copied separately
ssh origin "hack-browser-data dumpkeys" | \
  hack-browser-data restore --keys - --data-zip browser

核心特点

  • •Go
  • •browser
  • •browser-extension
  • •chrome
  • •edge

> 标签

Gobrowserbrowser-extensionchromeedge

暂无评论,来聊聊你的看法吧

> 工具信息

发布日期2026年8月1日
最后更新2026年9月9日
分类编程语言
定价开源

> 相关工具

T
TypeScript
JavaScript 的超集,为前端与全栈提供静态类型
P
Python
通用编程语言,广泛用于 Web、数据与 AI
G
Go
Google 推出的简洁高效系统语言
Baike.dev

baike.dev helps you discover great languages, frameworks, databases, DevOps and cloud-native tools.

Quick links

  • Home
  • All tools
  • Trending
  • Open source

About

  • About us
  • Community
  • News

Contribute

Found a great developer tool? Share it with the community.

Submit a tool
© 2026 baike.dev Developer EncyclopediaUpdated daily · Discover great developer tools