SharpChrome-Logins
NEW Credential AccessCollection WindowsActiveDirectory
SharpChrome (part of the SharpDPAPI project) extracts Chromium-based browser secrets - saved logins, cookies, and credit cards - by resolving the browser's DPAPI-protected AES state key and decrypting the login database. The logins command with /unprotect uses the current user's DPAPI keys directly to reveal stored passwords in plaintext. Run it in the target user's session (or supply /pvk: with the domain backup key); it also supports /browser:edge and cookies output for session hijacking. Command Reference: Target browser: Chrome (current user profile)