Repository navigation
Return of the Cookie Monster - #2851
carlospolop wants to merge 4 commits into
Conversation
|
merge |
|
Sunday editorial verdict: defer Documents post-compromise activation of Chrome DevTools Protocol inside a live Windows Chromium process, including the distinct process-isolation path, version-dependent symbol resolution, and failure constraints. Adds source-backed coverage of authenticated-browser artifact collection and interaction, with Windows credential-theft navigation and contextual detection guidance.
|
|
Sunday editorial verdict: defer Documents post-compromise activation of CDP inside authenticated Chrome and Edge processes, including the Windows Process Isolation variant, version-specific signature constraints, and browser-assisted collection workflows. Adds Windows credential-theft navigation to the canonical CDP page.
Editorial repairs:
|
|
Sunday editorial verdict: ready Documents post-compromise CDP activation inside authenticated Chrome and Edge processes, including a Process Isolation-compatible path and version-specific signature maintenance. It also covers browser-assisted collection, saved-password autofill constraints, and live session interaction without offline App-Bound Encryption decryption.
Editorial repairs:
|
|
merge |
|
Sunday editorial verdict: ready Documents post-compromise activation of CDP in live x64 Chrome and Edge processes, including Chrome Process Isolation handling, version-specific signature maintenance, and authenticated browser access without relaunching the profile. Adds source-backed CDP Toolkit workflows for browser artifacts, autofill-backed credential access, and interactive session use, with a Windows credential-theft navigation link.
Editorial repairs:
|
|
merge |
Blog URL
https://specterops.io/blog/2026/08/13/chrome-devtools-protocol-cookie-theft
Blog Title
Return of the Cookie Monster
Blog high summary
A post-compromise Windows technique injects into a live Chrome or Edge process and calls Chromium's internal
StartRemoteDebuggingServer, enabling CDP onlocalhost:9222without relaunching the browser. This preserves the user's authenticated profile despite Chrome 136+ launch-flag protections.CDP Toolkit can enumerate tabs, dump cookies, inspect history, bookmarks, extensions, passwords, capture screenshots, and browse through the user's session. Sysmon Event 8 plus Event 10
GrantedAccess=0x143acan indicate the injection.PR changes
Errors
mdbook build unavailable