Clankerusecase
MITRE ATT&CK detection coverage
← Back to main site
Home/ MITRE Matrix/ Lateral Movement/ T1550.004

T1550.004Web Session Cookie

T1550.004 — Web Session Cookie is a MITRE ATT&CK technique in the Lateral Movement tactic. Clankerusecase tracks 11 detection use cases covering it and 8 threat-intel articles citing it.

Lateral Movement
View on the matrix → Filter Detection Library MITRE official spec ↗
11Use cases
8Articles
0Sub-techniques
1Tactic

Use cases covering this technique (11)

[WEEKLY] Edge-service post-exploitation chain: internet-facing daemon → child shell or token redemption within 10 min of external request Internal actions · alerting DSPDD Okta Multiple Failed Requests to Access Applications ESCU actions · hunting P [LLM] Post-quishing cloud token replay: MFA-satisfied sign-in shortly after QR-attachment email Bespoke actions · alerting DSPDD [LLM] AiTM MFA-relay: successful Entra sign-in from AWS EC2 / hosting ASN Bespoke actions · hunting DSPDD [LLM] AitM session hijack: PaaS phishing-page visit followed by successful Entra sign-in from a different IP Bespoke actions · alerting DS [LLM] Gitea same-user auth failure + success from different IPs within 2 minutes Bespoke exploit · alerting SP [LLM] MantisBT self-registration (signup.php) followed by SOAP replay to mantisconnect.php from same source Bespoke exploit · hunting SP [LLM] First-seen SOAP client on MantisBT mantisconnect.php (new source, post-bypass admin activity) Bespoke exploit · hunting SP [LLM] FacturaScripts account takeover: /AdminPlugins access following filter[] SQLi from same source Bespoke actions · alerting SP [LLM] Kimai authenticated session activity with no preceding form-login POST (forged remember-me cookie) Bespoke exploit · hunting SP [LLM] Reuse of CircleCI-exfiltrated secrets / stolen SSO session from breach attacker IPs Bespoke actions · hunting DSΣPDDCSCW

Articles citing this technique (8)