Clankerusecase
MITRE ATT&CK detection coverage
← Back to main site
Home/ MITRE Matrix/ Collection/ T1185

T1185Browser Session Hijacking

T1185 — Browser Session Hijacking is a MITRE ATT&CK technique in the Collection tactic. Clankerusecase tracks 13 detection use cases covering it and 3 threat-intel articles citing it.

Collection
View on the matrix → Filter Detection Library MITRE official spec ↗
13Use cases
3Articles
0Sub-techniques
1Tactic

Use cases covering this technique (13)

ASL AWS Concurrent Sessions From Different Ips ESCU actions · hunting P AWS Concurrent Sessions From Different Ips ESCU actions · alerting P Azure AD Concurrent Sessions From Different Ips ESCU actions · alerting P O365 Concurrent Sessions From Different Ips ESCU actions · alerting P Windows Browser Process Launched with Unusual Flags ESCU actions · hunting P Windows Chrome Auto-Update Disabled via Registry ESCU actions · hunting P Windows Chrome Enable Extension Loading via Command-Line ESCU actions · hunting P Windows Chrome Extension Allowed Registry Modification ESCU actions · hunting P Windows Chromium Process Loaded Extension via Command-Line ESCU actions · hunting P [LLM] ChromEggscalator: Chromium launched with --remote-debugging-port for cookie/credential theft Bespoke actions · alerting DSΣPDDCS [LLM] LightRAG CVE-2026-61736: cross-origin credentialed read of /documents or /query (data exfil) Bespoke actions · hunting SP [LLM] LightRAG CVE-2026-61736: cross-origin DELETE of document store (destructive CORS abuse) Bespoke actions · alerting SP [LLM] Hoppscotch Mock Server stored XSS via GraphQL updateRESTUserRequest content-type override Bespoke exploit · hunting DSPDD

Articles citing this technique (3)