6.0 KiB
browser_dump - Dump Browser Credentials
Extract cookies, saved passwords (logins), and bookmarks from web browsers.
Description
The browser_dump command extracts encrypted credentials from web browsers and decrypts them using browser-specific methods. It supports Chrome and Firefox browsers.
Important: Only saved passwords (logins) are automatically reported to Mythic's credential store. Cookies are displayed in the output for manual use but are NOT stored as credentials.
Syntax
browser_dump <browser>
Parameters
browser(required): Browser to dump. Must be one of:chrome,firefox
Examples
browser_dump chrome
browser_dump firefox
Features
- Browser Support: Chrome, Firefox
- Credential Extraction: Cookies (display only), saved passwords, and bookmarks
- Automatic Decryption: Decrypts browser-protected credentials
- Credential Reporting: Automatically reports saved passwords to Mythic (cookies are NOT stored)
- Artifact Tracking: Reports credential access artifacts
- Profile Support: Firefox supports multiple profiles
- Smart Cookie Filtering: Only shows session cookies useful for authentication/impersonation (filters out tracking cookies)
Output
The command outputs three sections:
Cookies
============================================
|| Cookies ||
============================================
- URL: example.com
- Path: /
- Name: session_id
- Cookie: abc123def456...
Note: Cookies are displayed in the output but are NOT saved to Mythic's credential store. They are shown for manual use in session hijacking scenarios.
Bookmarks
============================================
|| Bookmarks ||
============================================
- Name: GitHub
- URL: https://github.com
Saved Logins
============================================
|| Saved logins ||
============================================
- URL: https://example.com
- Username: user@example.com
- Password: mypassword123
Credential Reporting
Only saved passwords (logins) are automatically reported to Mythic:
- Passwords: Reported as
plaintextcredential type - Realms: Automatically extracted from URLs (domain names)
- Cookies: NOT stored as credentials (displayed in output only)
Credentials appear in Mythic's Credentials page (click the key icon in the UI).
Cookie Filtering
The command intelligently filters cookies to show only those useful for authentication and session hijacking:
- Chrome: Only session cookies (no expiration) without security flags (HttpOnly, Secure)
- Firefox: Session cookies or authentication-related cookies (filters out tracking cookies)
Tracking cookies and cookies with security flags are excluded from the output.
Technical Details
Chrome (Chromium-based)
- App-Bound Key Extraction: Reads
Local Statefile and extracts the app-bound encryption key - Key Decryption: Decrypts the app-bound key using DPAPI (as SYSTEM and user)
- Data Decryption: Decrypts cookies and passwords using AES-256-GCM
- Database Access: Reads SQLite databases (
Cookies,Login Data)
Firefox
- Profile Detection: Reads
profiles.inito find all Firefox profiles - Database Access: Directly reads SQLite databases (
cookies.sqlite,places.sqlite,logins.json) - Password Decryption: Decrypts saved passwords using master key derivation
- Cookie Storage: Firefox stores cookies in plaintext (no decryption needed)
File Paths
Chrome
- Cookies:
%LOCALAPPDATA%\Google\Chrome\User Data\Default\Network\Cookies - Logins:
%LOCALAPPDATA%\Google\Chrome\User Data\Default\Login Data - Bookmarks:
%LOCALAPPDATA%\Google\Chrome\User Data\Default\Bookmarks - Local State:
%LOCALAPPDATA%\Google\Chrome\User Data\Local State
Firefox
- Profiles:
%APPDATA%\Mozilla\Firefox\profiles.ini - Cookies:
%APPDATA%\Mozilla\Firefox\Profiles\<profile>\cookies.sqlite - Logins:
%APPDATA%\Mozilla\Firefox\Profiles\<profile>\logins.json - Bookmarks:
%APPDATA%\Mozilla\Firefox\Profiles\<profile>\places.sqlite
OPSEC Considerations
- HIGH DETECTION RISK: Browser credential access is heavily monitored
- EDR/XDR Detection: Most security tools have specific rules for this activity
- File Access Monitoring: Access to browser databases triggers alerts
- Credential Theft Indicators: This is a primary indicator of attack (MITRE T1555)
- Elastic Security: Detects unsigned processes accessing browser stores
- Detection Timeframe: Detection is likely within minutes
Detection Mechanisms
- File access to browser credential databases
- Access to
Local Statefiles (Chrome) - Access to
profiles.ini(Firefox) - Behavioral analysis (credential extraction patterns)
- Credential theft detection rules
Best Practices
- Use
browser_infofirst to identify available browsers - Consider timing (off-hours may reduce detection)
- Ensure proper authorization before use
- Always requires approval from another operator
- Alternative: Manual extraction may have lower detection risk
Artifacts
The command automatically reports the following artifacts:
- Credential Access: Browser credential database access (Cookies, Login Data)
- File Read: Browser Local State file access (Chrome)
- File Read: Browser profiles.ini access (Firefox)
Related
Browser Information Command - Identify installed browsers
Credentials Support
OPSEC Guide
Command Category: System Operations
Requires Admin: No (but may need SYSTEM token for Chrome key decryption)
MITRE ATT&CK: T1555 - Credentials from Password Stores, T1539 - Steal Web Session Cookie, T1081 - Credentials in Files