Cybersecurity from Málaga · Networks, lures and threats

← Threats
MITRE ATT&CK technique · Lateral Movement

T1550.004 Web Session Cookie

Sub-technique of T1550 Use Alternate Authentication Material

Adversaries can use stolen session cookies to authenticate to web applications and services. This technique bypasses some multi-factor authentication protocols since the session is already authenticated.(Citation: Pass The Cookie) Authentication cookies are commonly used in web applications, including cloud-based services, after a user has authenticated to the service so credentials are not…

MITRE ATT&CK page ↗

Who uses it · with stories on Jábega

Sigma rules to hunt it

SigmaHQ has no rules for this technique.

Rules from SigmaHQ · Detection Rule License 1.1. Technique from MITRE ATT&CK®.