Use Alternate Authentication Material: Web Session Cookie

Threat Actors can use stolen session cookies to authenticate to web applications and services. This technique bypasses some multi-factor authentication protocols since the session is already authenticated.

ID: ATAGS-T1109.004
Sub-technique of:  ATAGS-T1109
Tactic: Defense Evasion
Targeted Components: Cloud Control Plane
Responsibility: Provider
Created: 18 April 2026
Last Modified: 18 April 2026

Mitigations

This type of attack technique cannot be easily mitigated with preventive controls since it is based on the abuse of system features.