// MITRE ATT&CK

T1606.001 · Web Cookies

🎯 Credential Access LinuxmacOSWindowsSaaSIaaS Sub-technique

Sub-technique of T1606 · Forge Web Credentials.

Adversaries may forge web cookies that can be used to gain access to web applications or Internet services. Web applications and services (hosted in cloud SaaS environments or on-premise servers) often use session cookies to authenticate and authorize user access. Adversaries may generate these coo...

How to detect & mitigate it

Detecting Web Cookies starts with your SIEM/EDR telemetry. Write a detection rule with the Sigma generator, analyze suspicious logs in the log analyzer, and place the technique on your coverage with the ATT&CK matrix.

Related techniques

Source: MITRE ATT&CK®. ATT&CK is a registered trademark of The MITRE Corporation. Content for educational purposes.