Special thanks to Steven Cacciaroni, Director of Business Development for Palo Alto Networks, and Faisal Pias, Partner Solutions Architect AWS for their collaboration in co-authoring this blog. Introduction Financial services institutions (FSIs) are increasingly migrating workloads to the cloud to improve scalability...
The System32 directory is a critical component of the Windows operating system, housing essential system files and libraries that are vital for the system’s operation. In the context of offensive security, this directory is significant because it con...
Recently Google published a blog about detecting browser data theft using Windows Event Logs.
There are some good points in the post for defenders on how to detect misuse of DPAPI calls attempting to grab sensitive browser data.
But, what about the Remote Debugging feature? This made me curious to revisit the state of the remote debugging feature of browsers for grabbing sensitive information, including cookies.
We discussed cookie theft techniques in the past, even presented about it at the CCC some 5+ years ago and helped add the TTP to the MITRE ATT&CK matrix.