{"id":"T1550.004","name":"Web Session Cookie","url":"https://attack.mitre.org/techniques/T1550/004","tactics":["lateral-movement"],"platforms":["IaaS","Office Suite","SaaS"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0074","stix_id":"x-mitre-detection-strategy--8d30c115-84f7-4fcc-ba22-96cb092d8114","name":"Detect Use of Stolen Web Session Cookies Across Platforms","url":"https://attack.mitre.org/detectionstrategies/DET0074","analytics":[{"id":"AN0201","stix_id":"x-mitre-analytic--8d43ac43-de80-4815-b992-6f49519ed340","name":"Analytic 0201","description":"Anomalous access to cloud web applications using session tokens without corresponding MFA/credential validation, often from unusual locations or device fingerprints.","url":"https://attack.mitre.org/detectionstrategies/DET0074#AN0201","platforms":["IaaS"],"log_source_references":[{"name":"AWS:CloudTrail","channel":"SessionToken used without preceding MFA or login event","data_component":"DC0007","data_component_name":"Web Credential Usage","log_source_slug":"aws-cloudtrail"},{"name":"AWS:CloudTrail","channel":"ConsoleLogin","data_component":"DC0067","data_component_name":"Logon Session Creation","log_source_slug":"aws-cloudtrail"}],"mutable_elements":[{"field":"TimeWindow","description":"How far back to check for legitimate MFA or login events before token usage"},{"field":"IPGeolocationDistance","description":"Threshold for flagging geographically impossible logins"}],"live":true,"detection_strategies":["DET0074"],"techniques":["T1550.004"]},{"id":"AN0202","stix_id":"x-mitre-analytic--32ace35c-66c4-48d7-a8bc-d81c65f4451b","name":"Analytic 0202","description":"Session cookie reuse on unmanaged browsers, devices, or client types deviating from user baseline (e.g., switching from Chrome to curl).","url":"https://attack.mitre.org/detectionstrategies/DET0074#AN0202","platforms":["SaaS"],"log_source_references":[{"name":"m365:unified","channel":"SessionId reused from different device/browser fingerprint","data_component":"DC0007","data_component_name":"Web Credential Usage","log_source_slug":"m365-unified"},{"name":"saas:okta","channel":"session.impersonation.start","data_component":"DC0002","data_component_name":"User Account Authentication","log_source_slug":"saas-okta"}],"mutable_elements":[{"field":"BrowserFingerprintMatch","description":"Tolerance for accepting small differences in user-agent headers"},{"field":"SessionReuseTimeout","description":"Time gap threshold between valid session creation and reuse"}],"live":true,"detection_strategies":["DET0074"],"techniques":["T1550.004"]},{"id":"AN0203","stix_id":"x-mitre-analytic--126cff4b-4ba7-4464-bfc8-4daabed5e05b","name":"Analytic 0203","description":"Web session tokens reused in native Office apps (e.g., Outlook, Teams) without associated token refresh or login behavior on the endpoint.","url":"https://attack.mitre.org/detectionstrategies/DET0074#AN0203","platforms":["Office Suite"],"log_source_references":[{"name":"m365:unified","channel":"UserLoggedIn","data_component":"DC0067","data_component_name":"Logon Session Creation","log_source_slug":"m365-unified"}],"mutable_elements":[{"field":"EndpointTokenSyncGap","description":"Allowed delta between endpoint login and cloud token reuse"}],"live":true,"detection_strategies":["DET0074"],"techniques":["T1550.004"]}],"live":true,"version":"1.0","techniques":["T1550.004"]}],"sigma_rules":[],"kev_cves":[],"_built":"2026-08-23 05:47 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}