Red Team | Looting Credentials from Modern Browsers

Red Team | Looting Credentials from Modern Browsers

🎙 Melvin Mejia 👥 70K 📅 February 17, 2026 ⏱ 30 min 👁 244 📄 expert opinion 🧭 2026-08-15
Available in: English (current) Français

Keywords

DPAPIAppBound EncryptionChromeCredential GuardRed Team

Summary

In this SANS Hack & Defend Summit 2025 presentation, Melvin Mejia, a senior red team operator, discusses the challenges of credential dumping on modern Windows systems and presents web browsers as an alternative target. He explains the Windows Data Protection API (DPAPI) and its role in securing browser secrets, then introduces AppBound Encryption, a new protection mechanism in Chromium-based browsers introduced in Chrome 127. Mejia details three techniques to bypass AppBound Encryption: code injection into Chrome, dropping a binary in the browser’s installation path, and replicating the elevation service logic. He provides proof-of-concept demonstrations for each method, highlighting the increased difficulty and detection opportunities. The talk concludes with the offensive security implications and the cat-and-mouse dynamic between mitigations and bypasses.

120 words

Critical Evaluation

Value of the Information & Strength of the Argument

The presentation provides valuable, actionable information for red teamers, detailing practical techniques with proof-of-concept code. The argumentation is solid, based on the speaker’s hands-on experience and references to public research. The step-by-step breakdown of DPAPI and AppBound encryption is clear and well-structured, making complex concepts accessible. However, the talk is primarily anecdotal and lacks formal citations or comparative analysis with other methods.

Scientific Rigor, Source Quality, Title Accuracy

The speaker references several public proof-of-concepts and researchers, including ‘ranasu’, ‘Alexander Hagena’, and ’no crash’, but does not provide direct URLs during the talk. The title accurately reflects the content, focusing on credential looting from modern browsers. The presentation is technically rigorous, with code snippets and explanations of underlying mechanisms, but the lack of formal citations and reliance on personal experience slightly reduce its scientific rigor.

143 words

Title / Content Match

The title accurately reflects the content, which focuses on techniques for extracting credentials from modern web browsers.

Quality & Reliability

8/10

Presentation by a senior red team operator with practical demonstrations and references to public proof-of-concepts. Content is technically accurate and up-to-date, but relies on anecdotal evidence and lacks peer-reviewed sources.

Key Moments

Cited Sources

  • Chrome Elevator by Alexander Hagena — Mentioned as a public proof-of-concept for process injection to bypass AppBound encryption.
  • Cookie decryption proof-of-concept by ranasu — Referenced as a proof-of-concept for cookie decryption that highlights key concepts.
  • Proof-of-concept by no crash — Mentioned as a proof-of-concept for dropping a binary in Chrome's installation path.
  • Proof-of-concept by zero edit — Referenced as a fork of ranasu's work adapted for password decryption.

Concurring Sources

  • Chrome Elevator by Alexander Hagena — Confirms the technique of process injection to bypass AppBound encryption.
  • Cookie decryption proof-of-concept by ranasu — Confirms the DPAPI and CNG decryption steps for Chrome cookies.

Contribution & Novelties

This talk provides a comprehensive and up-to-date overview of browser credential theft on modern Windows systems, specifically focusing on the recent AppBound Encryption mechanism. It offers practical, hands-on techniques for bypassing these protections, which are valuable for red teamers and security researchers. The presentation also highlights the evolving cat-and-mouse dynamic between browser security and offensive techniques.

Pour aller plus loin :

  • DPAPI documentation — Official Microsoft documentation on DPAPI.
  • AppBound Encryption blog post — Google’s official announcement of AppBound Encryption.
  • Chrome Elevator tool — Proof-of-concept for bypassing AppBound via process injection.

91 words

Radar Profile

The radar profile shows high scores in technical level and information quality, reflecting the advanced and practical nature of the content. The lower score in reliability is due to the lack of formal citations and reliance on personal experience.

Reliability 7/10