THREAT OPS › Threat News › Return of the Cookie Monster
Return of the Cookie Monster
<p class="wp-block-paragraph" id="h-tl-dr-cookie-protections-have-made-traditional-session-theft-harder-but-they-do-not-eliminate-the-value-of-an-authenticated-browser-session-to-adversaries-this-post-explores-enabling-the-chrome-devtools-protocol-cdp-inside-a-running-chromium-browser-to-perform-post-ex-activities-such-as-browser-enumeration-cookie-theft-and-browser-takeover"><em><strong>TL;DR: </
MITRE ATT&CK techniques
Indicators of compromise
- https://developer.chrome.com/blog/remote-debugging-porturl
- https://chromedevtools.github.io/devtools-protocol/url
- https://deathflamingo.com/blog/cdp_enabler/url
- https://chromium-browser-symsrv.commondatastorage.googleapis.com>url
- https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=90008url
- https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=90010url
- s.w.orgdomain