Skip to content
← LibraryTechnique entry
T1539Credential Access

Steal Web Session Cookie

Steal a session cookie (via XSS, MITM, cache poison) to take over an authenticated session without credentials.

§ Where this technique fits

T1539 is catalogued under the Credential Access tactic of the offensive-security kill-chain. It appears in 14 approved dossiers in the registry, typically at step 4.6 on average.

Authoritative reference: attack.mitre.org/techniques/T1539/.

§ Dossiers chaining this technique

§ What commonly comes next

  1. 01
    Valid Accounts
    T1078 · Initial Access
    seen 6×
  2. 02
    Certificate Transparency Monitoring
    PKI-CT-MONITOR · Reconnaissance
    seen 1×
  3. 03
    Mailbox Forwarding Rule
    M365-MAILBOX-FORWARD · Collection
    seen 1×
  4. 04
    Pass the Ticket
    T1550.003 · Lateral Movement
    seen 1×