Tag

#Session Hijacking

3 articles covering Session Hijacking across campaign analysis, detection engineering, and defender tradecraft.

Coverage

3 entries

Field Analysis

Blue TeamDetection & ValidationMay 31, 20267 min read

Chrome Binds the Cookie: A Defender's Brief on Device Bound Session Credentials

Chrome's Device Bound Session Credentials, now generally available and on by default for Workspace, tie session cookies to a device's security chip so a stolen cookie is useless off the machine it came from. Here is what it stops and what it does not.

Browse Other Tags

#Detection Engineering#OAuth#Credential Theft#Identity#Supply Chain#AiTM#Campaign Analysis#Infrastructure Intelligence#MFA Bypass#SaaS Security#Tradecraft Labs#ClickFix