Return of the Cookie Monster
Summary
This article explores how adversaries can still exploit authenticated browser sessions despite improved cookie protections by using the Chrome DevTools Protocol (CDP). It details methods for performing post-exploitation activities like browser enumeration, cookie theft, and browser takeover within a running Chromium browser.
IFF Assessment
FOE
The article details new techniques adversaries can use to steal authentication cookies and take over browser sessions, which is detrimental to defenders.
Defender Context
Defenders should be aware that traditional session theft methods may be evolving with the use of tools like the Chrome DevTools Protocol. Monitoring for unusual browser activity or the exploitation of authenticated sessions remains crucial.