EDR-Evasive Profile Stealer
Architecture, build-time backends, bypass methods, and extraction techniques (Windows off-screen, CDP, Linux Ozone) for an EDR-evasive Chromium profile stealer research series.
Part 1: Building an EDR-Evasive Chromium Profile Stealer - Architecture & Modular Backends for EDR EvasionExploring modular process launching and termination backends designed for EDR/AV evasion in a Chromium profile stealer. Research notes from Drew Alleman on...
Part 2: Implementing a Build-Time Backend Selection SystemBuilding the build.py script that injects selected launcher, terminator, sleep, and bypass backends at compile time. Research notes from Drew Alleman on...
Part 3: Designing a Reusable Architecture for Bypass MethodsDefining a clean three-layer structure (BypassMethod, Downloader, Manager) so new extraction techniques can be added with minimal changes.
Part 4: Windows Off-Screen Technique for Stealing Chromium ProfilesAbusing Chromium's automatic download of non-renderable files by launching the browser completely off-screen with --window-position=-32000,-32000.
Part 5: Extracting Chromium Profiles with the Chrome DevTools Protocol (CDP)Using the Chrome DevTools Protocol and cdp_minimal to read local profile databases through a legitimate browser process.
Part 6: Linux Ozone Technique - Headless Chromium Without Process ExplosionUsing --ozone-platform=headless to strip the GUI while still respecting Chromium's process singleton for clean multi-file downloads.