Forge Web Credentials: Web Cookies T1606.001

Tactic: Credential Access

Adversaries may forge web cookies that can be used to gain access to web applications or Internet services. Web applications and services (hosted in cloud SaaS environments or on-premise servers) often use session cookies to authenticate and authorize user access.

Events covered

1 catalog event is tagged with this technique by at least one rule.

Authoring guide

These 1 rule share fields, values, and exclusions.

Fields filtered most (3 distinct)

These fields appear most often in rule filters.

FieldRulesHowSample values
ActionType1starts_with 1AppControl
GlobalPrevalence1lt 1250
file_name1eq 1microsoftaccounttokenprovider.dll

Top indicator values (3 distinct)

These values appear most often in rule predicates.

FieldKindValueRules (here)Corpus reach
ActionTypestarts_with
AppControl
15
GlobalPrevalencelt
250
14
file_nameeq
microsoftaccounttokenprovider.dll
1

Rules under this technique

These vendors publish rules tagged with this technique.

Platform: Cross-platform

Domain: Unspecified

Kusto 1 rule