1200KM / simulation
T1539 Steal Web Session Cookie — Attack Simulation
An adversary may steal web application or service session cookies and use them to gain access to web applications or Internet services as an authenticated user without needing credentials. Web applications and services often use session cookies as an authentication token after a user has authenticated to a website. Cookies are often valid for an extended period of time, even if the web application is not actively used. Cookies can be found on…
Technique description
An adversary may steal web application or service session cookies and use them to gain access to web applications or Internet services as an authenticated user without needing credentials. Web applications and services often use session cookies as an authentication token after a user has authenticated to a website. Cookies are often valid for an extended period of time, even if the web application is not actively used. Cookies can be found on…
At least one platform-compatible Atomic procedure is documented. Individual review, lab prerequisites, and validation remain required.
Official ATT&CK definition · Detection rules and anomaly models
Documented simulation candidates
- Steal Chrome Cookies (Windows)
Procedure 26a6b840-4943-4965-8df5-ef1f9a282440; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
- Steal Firefox Cookies (Windows)
Procedure 4b437357-f4e9-4c84-9fa6-9bcee6f826aa; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
- Steal Chrome v127+ cookies via Remote Debugging (Windows)
Procedure b647f4ee-88de-40ac-9419-f17fac9489a7; elevation not declared required; cleanup not declared. Not executed or individually validated.
- Steal Chrome Cookies via Remote Debugging (Mac)
Procedure e43cfdaf-3fb8-4a45-8de0-7eee8741d072; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
- Copy Safari BinaryCookies files using AppleScript
Procedure e57ba07b-3a33-40cd-a892-748273b9b49a; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
Connected ecosystem references
Linked tags
Detection and collection
Attack tools
Threat actor context
These are explicit actor-to-technique associations in the existing Threat Matrix snapshot, not attribution of an event or proof that a detector identifies the actor. No tool-to-actor relationship is inferred.
Existing research
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.