kevmap

TechniquesT1539 › AN1406

AN1406 Analytic 1406

SaaS · attack.mitre.org · ATT&CK Enterprise v19.2

<p>Detects use of session cookies or authentication tokens from unusual user agents or locations. Identifies token reuse without reauthentication or attempts to bypass MFA using previously stolen cookies.</p>
Detects
T1539 Steal Web Session Cookie
Part of
DET0509 Detection of Web Session Cookie Theft via File, Memory, and Network Artifacts

Log sources and channels

Exactly as MITRE states them in x_mitre_log_source_references. Where a channel is vague, it is vague in the source; kevmap does not tidy it.

Log sourceChannelData component
saas:googleworkspacelogin with reused session token and mismatched user agent or IPDC0002 User Account Authentication
saas:oktasession.token.reuseDC0067 Logon Session Creation

Mutable elements

Parameters MITRE marks as environment-specific. These are the knobs you are expected to tune; they are why an analytic is not a rule.

FieldDescription
TokenReuseTimeWindowMax allowed delta between token issuance and second use
UserAgentAnomalyScoreDeviation score from normal browser/device fingerprint
GeoLocationAnomalyScoreDeviation in IP region or ASN per user profile