Drew AllemanOffensive Security

Blog / Red Team / EDR-Evasive Profile Stealer

EDR-Evasive Profile Stealer

Architecture, build-time backends, bypass methods, and extraction techniques (Windows off-screen, CDP, Linux Ozone) for an EDR-evasive Chromium profile stealer research series.

complete· 6 parts

  1. Part 1: Building an EDR-Evasive Chromium Profile Stealer - Architecture & Modular Backends for EDR Evasion

    2026-08-01

    Exploring modular process launching and termination backends designed for EDR/AV evasion in a Chromium profile stealer. Research notes from Drew Alleman on...

  2. Part 2: Implementing a Build-Time Backend Selection System

    2026-08-01

    Building the build.py script that injects selected launcher, terminator, sleep, and bypass backends at compile time. Research notes from Drew Alleman on...

  3. Part 3: Designing a Reusable Architecture for Bypass Methods

    2026-08-01

    Defining a clean three-layer structure (BypassMethod, Downloader, Manager) so new extraction techniques can be added with minimal changes.

  4. Part 4: Windows Off-Screen Technique for Stealing Chromium Profiles

    2026-08-01

    Abusing Chromium's automatic download of non-renderable files by launching the browser completely off-screen with --window-position=-32000,-32000.

  5. Part 5: Extracting Chromium Profiles with the Chrome DevTools Protocol (CDP)

    2026-08-01

    Using the Chrome DevTools Protocol and cdp_minimal to read local profile databases through a legitimate browser process.

  6. Part 6: Linux Ozone Technique - Headless Chromium Without Process Explosion

    2026-08-01

    Using --ozone-platform=headless to strip the GUI while still respecting Chromium's process singleton for clean multi-file downloads.