T1550.004 Web Session Cookie
Subtécnica de T1550 Use Alternate Authentication Material
Adversaries can use stolen session cookies to authenticate to web applications and services. This technique bypasses some multi-factor authentication protocols since the session is already authenticated.(Citation: Pass The Cookie) Authentication cookies are commonly used in web applications, including cloud-based services, after a user has authenticated to the service so credentials are not…
Quién la usa · con noticias en Jábega
Reglas Sigma para cazarla
SigmaHQ no tiene reglas para esta técnica.
Reglas de SigmaHQ · Detection Rule License 1.1. Técnica de MITRE ATT&CK®.