Use Alternate Authentication Material: Web Session Cookie T1550.004
Tactic: Lateral Movement
Adversaries can use stolen session cookies to authenticate to web applications and services. This technique bypasses some multi-factor authentication protocols since the session is already authenticated.
Authoring guide
These 8 rules share fields, values, and exclusions.
Fields filtered most (40 distinct)
These fields appear most often in rule filters.
Top indicator values (44 distinct)
These values appear most often in rule predicates.
Exclusions (25 distinct)
These values appear most often in top-level exclusions.
Rules under this technique
These vendors publish rules tagged with this technique.
Sigma 2 rules
Elastic 4 rules
- Entra ID OAuth User Impersonation to Microsoft Graph
- Multiple Device Token Hashes for Single Okta Session
- Multiple Okta Sessions Detected for a Single User
- Okta AiTM Session Cookie Replay