Recently Google published a blog about detecting browser data theft using Windows Event Logs.
There are some good points in the post for defenders on how to detect misuse of DPAPI calls attempting to grab sensitive browser data.
But, what about the Remote Debugging feature? This made me curious to revisit the state of the remote debugging feature of browsers for grabbing sensitive information, including cookies.
We discussed cookie theft techniques in the past, even presented about it at the CCC some 5+ years ago and helped add the TTP to the MITRE ATT&CK matrix.