Clankerusecase
MITRE ATT&CK detection coverage
← Back to main site
Home/ MITRE Matrix/ Collection/ T1185

T1185Browser Session Hijacking

T1185 — Browser Session Hijacking is a MITRE ATT&CK technique in the Collection tactic. Clankerusecase tracks 17 detection use cases covering it and 5 threat-intel articles citing it.

Collection
View on the matrix → Filter Detection Library MITRE official spec ↗
17Use cases
5Articles
0Sub-techniques
1Tactic

Use cases covering this technique (17)

ASL AWS Concurrent Sessions From Different Ips ESCU actions · hunting P AWS Concurrent Sessions From Different Ips ESCU actions · alerting P Azure AD Concurrent Sessions From Different Ips ESCU actions · alerting P O365 Concurrent Sessions From Different Ips ESCU actions · alerting P Windows Browser Process Launched with Unusual Flags ESCU actions · hunting P Windows Chrome Auto-Update Disabled via Registry ESCU actions · hunting P Windows Chrome Enable Extension Loading via Command-Line ESCU actions · hunting P Windows Chrome Extension Allowed Registry Modification ESCU actions · hunting P Windows Chromium Process Loaded Extension via Command-Line ESCU actions · hunting P [LLM] AmnesiaStealer stream_module: headless Chromium launched with remote-debugging + hardening-off flags Bespoke actions · alerting DSΣPCS [LLM] AmnesiaStealer C2/relay egress to Amnesia Panel host (allllowef.space / aoitour.com) Bespoke c2 · alerting DSΣPCS [LLM] macOS headless Chromium launched with remote-debugging (CDP browser hijack) Bespoke actions · alerting DSΣPCS [LLM] SectopRAT in-browser proxy /churl traffic mirroring to attacker IPs Bespoke c2 · hunting DSΣPDDCS [LLM] XCSSET v40 Chrome launched with CDP remote-debugging enabled (browser hijack) Bespoke c2 · hunting DSΣPCS [LLM] XCSSET v40 chrome_remote CDP backdoor binary execution Bespoke install · alerting DSΣPCS [LLM] LightRAG CVE-2026-61736: cross-origin credentialed read of /documents or /query (data exfil) Bespoke actions · hunting SP [LLM] LightRAG CVE-2026-61736: cross-origin DELETE of document store (destructive CORS abuse) Bespoke actions · alerting SP

Articles citing this technique (5)