Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Detection Strategies DET0074 — Detect Use of Stolen Web Session Cookies Across Platforms
DET0074

Detect Use of Stolen Web Session Cookies Across Platforms

3 analytic(s) · 1 technique(s) detected

Analytics

3
AN0201 Analytic 0201
IaaS

Anomalous access to cloud web applications using session tokens without corresponding MFA/credential validation, often from unusual locations or device fingerprints.

AWS:CloudTrail SessionToken used without preceding MFA or login event AWS:CloudTrail ConsoleLogin
[TimeWindow] How far back to check for legitimate MFA or login events before token usage
[IPGeolocationDistance] Threshold for flagging geographically impossible logins
AN0202 Analytic 0202
SaaS

Session cookie reuse on unmanaged browsers, devices, or client types deviating from user baseline (e.g., switching from Chrome to curl).

m365:unified SessionId reused from different device/browser fingerprint saas:okta session.impersonation.start
[BrowserFingerprintMatch] Tolerance for accepting small differences in user-agent headers
[SessionReuseTimeout] Time gap threshold between valid session creation and reuse
AN0203 Analytic 0203
Office Suite

Web session tokens reused in native Office apps (e.g., Outlook, Teams) without associated token refresh or login behavior on the endpoint.

m365:unified UserLoggedIn
[EndpointTokenSyncGap] Allowed delta between endpoint login and cloud token reuse

Detected Techniques

1

Lateral Movement (1)

Details

MITRE ID
DET0074
STIX ID
x-mitre-detection-strategy--8d30c115-84f7-4fcc-ba22-96cb092d8114
Analytics
3
Techniques Detected
1
By Tactic
Lateral Movement
1
Leaving Threaticon

This link opens an external site that isn't part of the platform.