← All hunts high TLP:CLEAR

Session Hijacking and Replay Investigation

An adversary has stolen session cookies from a high-value endpoint and replayed them from a hosting network to bypass MFA and access corporate resources.

Based on research by Elastic Security Labs 2026-10-09 10 steps · 3 queries T1133 T1550.004 T1555.003

Brief

The Shift from Credentials to Sessions

As organizations strengthen MFA requirements, adversaries shift their focus from stealing passwords to hijacking active sessions. The recent work by Elastic Security Labs on Introducing AlertZero: Inbox zero for your alert queue highlights the scale of telemetry that SOC teams must navigate. This hunt addresses a specific gap in automated detection: the correlation between a suspicious login in the cloud and the silent theft of browser material on a workstation.

How the Hunt Flows

The hunt begins on the hb_auth_signin surface. It scopes the investigation to high-value accounts, such as executives or administrators, and filters for successful sign-ins originating from known proxies or hosting providers. This first step identifies the specific workstations associated with these users during the time of the suspicious authentication.

Once the hunt scopes the relevant hosts, it pivots to hb_process_activity to find rare binaries. The query baselines process execution across the fleet, highlighting any executable running on fewer than three hosts. This identifies potential custom scripts or infostealers that an adversary uses to harvest credentials.

Simultaneously, the hunt examines the hb_file_activity surface. It looks for non-browser processes accessing sensitive files like Chrome's 'Cookies', 'Login Data', or 'Local State' files. By excluding legitimate browser executables, the hunt surfaces unauthorized access to the session material needed for a replay attack.

In the final phase, a triage agent or analyst weighs the evidence from both the identity and endpoint surfaces. A match occurs when a workstation shows unauthorized cookie access followed by a suspicious sign-in from that same user. If the evidence meets the threshold, the hunt provides automated actions to isolate the host and revoke all active identity provider sessions for the affected user.

Blind Spots and Limitations

This hunt relies on granular endpoint telemetry. If the workstation configuration does not include file-read auditing for browser profiles, the theft itself remains invisible. Additionally, the accuracy of the initial scoping depends on the identity provider correctly labeling hosting networks and proxies. If an adversary uses a residential proxy that appears as a standard ISP, the sign-in may not trigger the initial scoping query.

Running the Hunt

This hunt is a hunt.md playbook. It is designed to be imported into Huntbase or any runtime that supports the open hunt.md standard. Because it correlates data across identity and endpoint surfaces, it functions as a periodic hunt rather than a single-surface detection rule. This structure allows it to provide high-confidence leads without the noise typically associated with monitoring file access on browser profiles.

To run it, provide the list of high-value usernames and define the lookback window for your environment. The playbook handles the cross-surface joins and provides the triage steps necessary to confirm a session hijacking incident.

Steps

  1. Suspicious sign-ins for target accounts

    Query · scoping

    The hunt finds successful sign-ins from proxies or distant countries for target users to scope the endpoint investigation.

    reads hb_auth_signinsql
    SELECT DISTINCT src_endpoint_hostname AS device_hostname, actor_user_name, src_endpoint_ip, src_location_country, is_proxy, time FROM hb_auth_signin WHERE instr(',' || '{{target_users}}' || ',', ',' || LOWER(actor_user_name) || ',') > 0 AND status_id = 1 AND (is_proxy = 'true' OR src_location_country IS NOT NULL) AND src_endpoint_hostname IS NOT NULL AND time >= datetime('now', '-{{lookback_days}} days')

    What a hit looks like. Rows map suspicious external logins to internal workstation names. Silence means no suspicious external auth was recorded for these users.

  2. Rare binary baseline

    Query · baseline

    The hunt identifies rare processes running on the scoped hosts that might harvest cookies.

    reads hb_process_activitysql
    SELECT LOWER(process_name) AS proc, COUNT(DISTINCT device_hostname) AS hosts, MIN(time) AS first_seen FROM hb_process_activity WHERE ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY proc HAVING hosts < 3

    What a hit looks like. The query returns processes unique to a scoped host. Common software should be filtered out by the count.

  3. Weigh the evidence

    Agent triage

    The agent correlates suspicious sign-ins with rare processes and cookie access to confirm whether an adversary hijacked the session.

  4. Route on verdict

    Decision

    The decision routes the investigation based on the agent verdict.

  5. Isolate host

    Response action

    The analyst isolates the compromised host to prevent data exfiltration.

  6. Revoke identity sessions

    Response action

    The analyst invalidates the replayed session to stop the attacker's access.

  7. Analyst review

    Analyst task

    The analyst performs a final confirmation of the incident findings.

  8. Close out

    Analyst task

    Document the findings when no malicious activity is confirmed.

Coverage

Scenario coverage

StageCoveredHow, or why not
Browser Session Material Theft
T1555.003
Yes rare-binaries, unauthorized-cookie-access
Impossible Travel via Session Replay
T1133 · T1550.004
Yes suspicious-sign-ins

Blind spots

  • Needs hb_file_activity with file-read auditing. Endpoint configurations often only audit file writes; cookie theft via reading would be invisible. It would answer whether a process read browser files silently.
  • Needs Accurate proxy and hosting network identification in hb_auth_signin. If the identity provider fails to flag a hosting network as a proxy, the replay may appear as a legitimate sign-in. It would answer whether a login originated from a hosting network.

Parameters & data

Parameters

ParameterTypeDefaultWhat it is
browser_excllist[string]chrome.exe, msedge.exe, firefox.exe, brave.exe, opera.exeLegitimate browser processes to exclude from file access checks.
lookback_daysnumber14Days of history to examine.
scope_hostslist[host]—Hosts to narrow the search for cookie theft.
target_userslist[string]cfo@corpHigh-value accounts to monitor for anomalous logins.

Telemetry

SourceCategoryTelemetry
Endpoint telemetry (hb_ surfaces)endpointendpoint
Identity / sign-in telemetryidentityidentity

Source

Download hunt.md Definition (JSON) An open hunt.md file; it runs anywhere that reads the format.
---
analysis: A single rule might detect unauthorized cookie access, but the hunt correlates
  that with identity-level anomalies (impossible travel, proxy logins) across separate
  telemetry surfaces to confirm a hijacking incident without excessive noise.
blind_spots:
- id: missing-file-read-telemetry
  question: whether a process read browser files silently
  requires: hb_file_activity with file-read auditing
  risk: Endpoint configurations often only audit file writes; cookie theft via reading
    would be invisible.
  stage: credential-access-session-theft
- id: identity-proxy-labeling
  question: whether a login originated from a hosting network
  requires: Accurate proxy and hosting network identification in hb_auth_signin
  risk: If the identity provider fails to flag a hosting network as a proxy, the replay
    may appear as a legitimate sign-in.
  stage: initial-access-session-replay
coverage:
- stage: credential-access-session-theft
  status: covered
  steps:
  - rare-binaries
  - unauthorized-cookie-access
- stage: initial-access-session-replay
  status: covered
  steps:
  - suspicious-sign-ins
guardrails:
  claims: no_unsupported
  evidence: citation_required
  missing_data: not_benign
  telemetry: untrusted
hunt:
  applicability: campaign-specific
  handoff: keep-as-periodic-hunt
  justification: Session replay is a primary method for bypassing MFA. Proving its
    absence across targeted high-value accounts provides critical assurance against
    sophisticated account takeover attempts.
  methodology: model-assisted
  trigger: intel-report
hypothesis: An adversary has stolen session cookies from a high-value endpoint and
  replayed them from a hosting network to bypass MFA and access corporate resources.
labels:
- hunt
- attack.t1133
- attack.t1555.003
- attack.t1550.004
- credential access
- initial access
name: Session Hijacking and Replay Investigation
parameters:
  browser_excl:
    default:
    - chrome.exe
    - msedge.exe
    - firefox.exe
    - brave.exe
    - opera.exe
    description: Legitimate browser processes to exclude from file access checks.
    from:
      kind: manual
      observed: '2026-10-08'
      ref: Common Browser Process Names
    type: list[string]
  lookback_days:
    default: '14'
    description: Days of history to examine.
    from:
      kind: manual
      observed: '2026-10-08'
      ref: Standard Hunt Window
    type: number
  scope_hosts:
    default: []
    description: Hosts to narrow the search for cookie theft.
    type: list[host]
  target_users:
    default:
    - cfo@corp
    description: High-value accounts to monitor for anomalous logins.
    from:
      kind: article
      observed: '2026-10-08'
      ref: Introducing AlertZero
    type: list[string]
provenance:
  authors:
  - name: Huntbase hunt generation
    org: huntbase.io
  generated:
    by: huntbase-hunt-generation
    from: https://www.elastic.co/security-labs/blog/ai-soc-automation-alertzero
    gates:
    - dry-run
    - lint
    - critic
    model: hb_google/gemini-3-flash-preview
rationale: The analyst starts with high-value executive accounts (CFO, CEO) and administrators.
  The hunt focuses endpoint scoping on hosts whose names appear as src_endpoint_hostname
  in anomalous sign-in events.
references:
- name: 'Introducing AlertZero: Inbox zero for your alert queue'
  url: https://www.elastic.co/security-labs/blog/ai-soc-automation-alertzero
related:
- hunt: mfa-push-fatigue-attack
  reason: This hunt focuses on session reuse, while push fatigue focuses on the coercion
    of a new MFA event.
  relation: out-of-scope-alternative
scenario:
  stages:
  - name: Browser Session Material Theft
    observables:
    - unsigned process
    - browser session material
    - cfo@corp
    slug: credential-access-session-theft
    tactic: credential-access
    techniques:
    - T1555.003
  - name: Impossible Travel via Session Replay
    observables:
    - Boston
    - distant hosting network
    - same session identifier
    - no fresh MFA event
    - cfo@corp
    slug: initial-access-session-replay
    tactic: initial-access
    techniques:
    - T1133
    - T1550.004
  summary: An attacker uses an unsigned process on a compromised endpoint to steal
    browser session material, allowing them to hijack an executive account. The stolen
    session is then replayed from a distant hosting network to bypass multi-factor
    authentication, resulting in an unauthorized login that manifests as an impossible-travel
    event.
severity: high
targets:
  analyst:
    name: Tier-2 analyst
    role: analyst
  endpoint:
    category: endpoint
    name: Endpoint telemetry (hb_ surfaces)
    telemetry:
    - endpoint
  hunter:
    agent: true
    name: Hunt agent
  identity:
    category: identity
    name: Identity / sign-in telemetry
    telemetry:
    - identity
tlp: clear
type: investigation
---


# Session Hijacking and Replay Investigation

This hunt identifies account takeovers caused by session replay. It correlates anomalous sign-in events like impossible travel or proxy usage with endpoint evidence of browser cookie theft. By finding where unauthorized processes have accessed sensitive browser profile data on the same hosts used by targeted accounts, the hunt distinguishes between legitimate remote access and malicious session identifier reuse. It focuses on the pattern of session identifier reuse without a fresh MFA event, originating from hosting network IPs or anonymizing proxies.

## suspicious-sign-ins
<!-- Suspicious sign-ins for target accounts -->
The hunt finds successful sign-ins from proxies or distant countries for target users to scope the endpoint investigation.

```sqlite target=identity role=scoping params=(target_users=target_users, lookback_days=lookback_days)
~~~yaml
expected: Rows map suspicious external logins to internal workstation names. Silence
  means no suspicious external auth was recorded for these users.
reads:
- src_endpoint_hostname
- actor_user_name
- src_endpoint_ip
- src_location_country
- is_proxy
- status_id
- time
silence: not_evidence_of_absence
source: hb_auth_signin
verified: dry-run
verified_at: '2026-10-09'
~~~
SELECT DISTINCT src_endpoint_hostname AS device_hostname, actor_user_name, src_endpoint_ip, src_location_country, is_proxy, time FROM hb_auth_signin WHERE instr(',' || '{{target_users}}' || ',', ',' || LOWER(actor_user_name) || ',') > 0 AND status_id = 1 AND (is_proxy = 'true' OR src_location_country IS NOT NULL) AND src_endpoint_hostname IS NOT NULL AND time >= datetime('now', '-{{lookback_days}} days')
```

## correlate-evidence
<!-- Correlate with endpoint activity -->
parallel:
- → rare-binaries
- → unauthorized-cookie-access
join: → triage-agent

## rare-binaries
<!-- Rare binary baseline -->
The hunt identifies rare processes running on the scoped hosts that might harvest cookies.

```sqlite target=endpoint role=baseline params=(scope_hosts=scope_hosts, lookback_days=lookback_days)
~~~yaml
baseline:
  compare: first_seen
  window: '{{lookback_days}}d'
expected: The query returns processes unique to a scoped host. Common software should
  be filtered out by the count.
prevalence:
  by: device_hostname
  key:
  - process_name
  rare_below: 3
reads:
- process_name
- device_hostname
- time
silence: not_evidence_of_absence
source: hb_process_activity
verified: dry-run
verified_at: '2026-10-09'
~~~
SELECT LOWER(process_name) AS proc, COUNT(DISTINCT device_hostname) AS hosts, MIN(time) AS first_seen FROM hb_process_activity WHERE ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND time >= datetime('now', '-{{lookback_days}} days') GROUP BY proc HAVING hosts < 3
```

## unauthorized-cookie-access
<!-- Access to browser session material -->
The hunt detects processes reading browser cookie files while excluding the browser itself.

```sqlite target=endpoint role=detection-candidate params=(scope_hosts=scope_hosts, lookback_days=lookback_days, browser_excl=browser_excl)
~~~yaml
expected: A row shows a non-browser process accessing browser material. Silence means
  the file surface did not see unauthorized reads.
reads:
- device_hostname
- process_name
- file_path
- actor_user_name
- time
silence: not_evidence_of_absence
source: hb_file_activity
verified: dry-run
verified_at: '2026-10-09'
~~~
SELECT device_hostname, process_name, file_path, actor_user_name, time FROM hb_file_activity WHERE ('{{scope_hosts}}' = '' OR instr(',' || '{{scope_hosts}}' || ',', ',' || device_hostname || ',') > 0) AND (LOWER(file_path) LIKE '%\\cookies' OR LOWER(file_path) LIKE '%\\login data' OR LOWER(file_path) LIKE '%\\local state') AND NOT instr(',' || '{{browser_excl}}' || ',', ',' || LOWER(process_name) || ',') > 0 AND time >= datetime('now', '-{{lookback_days}} days')
```

## triage-agent
<!-- Weigh the evidence -->
```agent target=hunter
cite: required
context:
- suspicious-sign-ins
- rare-binaries
- unauthorized-cookie-access
max_iterations: 6
objective: Determine if a scoped host shows unauthorized browser material access followed
  by a suspicious sign-in for that same user from a proxy or hosting network.
success_criteria: A verdict of malicious | suspicious | benign per host.
tools:
- endpoint
- identity
```

## route-on-verdict
<!-- Route on verdict -->
if~: "the triage verdict is malicious for at least one host" (confidence: high, judge=hunter)
then: → isolate-host
indeterminate: → analyst-review
unavailable: → analyst-review (blind_spot: missing-file-read-telemetry)
else: → close-out

## isolate-host
<!-- Isolate host -->
```action target=endpoint
~~~yaml
approval: required
~~~
Isolate the host using the endpoint agent and collect the identified rare binary for forensics.
```
→ revoke-identity-sessions

## revoke-identity-sessions
<!-- Revoke identity sessions -->
```action target=identity
~~~yaml
approval: required
~~~
Revoke all active OAuth and SAML sessions for the affected user in the identity provider to invalidate replayed cookies.
```
→ analyst-review

## analyst-review
<!-- Analyst review -->
```manual target=analyst
Review the process tree for the identified binary and the user's recent cloud API activity for signs of exfiltration occurring after the suspicious login.
```
→ end

## close-out
<!-- Close out -->
```manual target=analyst
Record the examined time window and any benign explanations for suspicious sign-ins, such as authorized corporate VPN usage or verified travel.
```
→ end

Run it

Take this hunt into your environment.

Open it in Huntbase to run every step against your own connections, with Scout weighing the evidence and your analysts in command. Or take the open hunt.md file anywhere that reads the format.

Machine-drafted by huntbase-hunt-generation using hb_google/gemini-3-flash-preview, gated by dry-run, lint, critic, then reviewed by a person.