Esc
Browser Session Hijacking - T1185
(ATT&CK® Technique)
Definition
Adversaries may take advantage of security vulnerabilities and inherent functionality in browser software to change content, modify user-behaviors, and intercept information as part of various browser session hijacking techniques.
D3FEND Inferred Relationships
Browse the D3FEND knowledge graph by clicking on the nodes below.
graph LR; T1185["Browser Session Hijacking"] --> |produces| WebNetworkTraffic["Web Network Traffic"]; class T1185 OffensiveTechniqueNode; class WebNetworkTraffic ArtifactNode; click WebNetworkTraffic href "/dao/artifact/d3f:WebNetworkTraffic"; click T1185 href "/offensive-technique/attack/T1185/"; click WebNetworkTraffic href "/dao/artifact/d3f:WebNetworkTraffic"; NetworkTrafficFiltering["Network Traffic Filtering"] --> | filters | WebNetworkTraffic["Web Network Traffic"]; NetworkTrafficFiltering["Network Traffic Filtering"] -.-> | may-isolate | T1185["Browser Session Hijacking"] ; class NetworkTrafficFiltering DefensiveTechniqueNode; class WebNetworkTraffic ArtifactNode; click NetworkTrafficFiltering href "/technique/d3f:NetworkTrafficFiltering"; Client-serverPayloadProfiling["Client-server Payload Profiling"] --> | analyzes | WebNetworkTraffic["Web Network Traffic"]; Client-serverPayloadProfiling["Client-server Payload Profiling"] -.-> | may-detect | T1185["Browser Session Hijacking"] ; class Client-serverPayloadProfiling DefensiveTechniqueNode; class WebNetworkTraffic ArtifactNode; click Client-serverPayloadProfiling href "/technique/d3f:Client-serverPayloadProfiling"; NetworkTrafficCommunityDeviation["Network Traffic Community Deviation"] --> | analyzes | WebNetworkTraffic["Web Network Traffic"]; NetworkTrafficCommunityDeviation["Network Traffic Community Deviation"] -.-> | may-detect | T1185["Browser Session Hijacking"] ; class NetworkTrafficCommunityDeviation DefensiveTechniqueNode; class WebNetworkTraffic ArtifactNode; click NetworkTrafficCommunityDeviation href "/technique/d3f:NetworkTrafficCommunityDeviation"; PerHostDownload-UploadRatioAnalysis["Per Host Download-Upload Ratio Analysis"] --> | analyzes | WebNetworkTraffic["Web Network Traffic"]; PerHostDownload-UploadRatioAnalysis["Per Host Download-Upload Ratio Analysis"] -.-> | may-detect | T1185["Browser Session Hijacking"] ; class PerHostDownload-UploadRatioAnalysis DefensiveTechniqueNode; class WebNetworkTraffic ArtifactNode; click PerHostDownload-UploadRatioAnalysis href "/technique/d3f:PerHostDownload-UploadRatioAnalysis"; UserGeolocationLogonPatternAnalysis["User Geolocation Logon Pattern Analysis"] --> | analyzes | WebNetworkTraffic["Web Network Traffic"]; UserGeolocationLogonPatternAnalysis["User Geolocation Logon Pattern Analysis"] -.-> | may-detect | T1185["Browser Session Hijacking"] ; class UserGeolocationLogonPatternAnalysis DefensiveTechniqueNode; class WebNetworkTraffic ArtifactNode; click UserGeolocationLogonPatternAnalysis href "/technique/d3f:UserGeolocationLogonPatternAnalysis"; ProtocolMetadataAnomalyDetection["Protocol Metadata Anomaly Detection"] --> | analyzes | WebNetworkTraffic["Web Network Traffic"]; ProtocolMetadataAnomalyDetection["Protocol Metadata Anomaly Detection"] -.-> | may-detect | T1185["Browser Session Hijacking"] ; class ProtocolMetadataAnomalyDetection DefensiveTechniqueNode; class WebNetworkTraffic ArtifactNode; click ProtocolMetadataAnomalyDetection href "/technique/d3f:ProtocolMetadataAnomalyDetection"; RemoteTerminalSessionDetection["Remote Terminal Session Detection"] --> | analyzes | WebNetworkTraffic["Web Network Traffic"]; RemoteTerminalSessionDetection["Remote Terminal Session Detection"] -.-> | may-detect | T1185["Browser Session Hijacking"] ; class RemoteTerminalSessionDetection DefensiveTechniqueNode; class WebNetworkTraffic ArtifactNode; click RemoteTerminalSessionDetection href "/technique/d3f:RemoteTerminalSessionDetection"; NetworkTrafficSignatureAnalysis["Network Traffic Signature Analysis"] --> | analyzes | WebNetworkTraffic["Web Network Traffic"]; NetworkTrafficSignatureAnalysis["Network Traffic Signature Analysis"] -.-> | may-detect | T1185["Browser Session Hijacking"] ; class NetworkTrafficSignatureAnalysis DefensiveTechniqueNode; class WebNetworkTraffic ArtifactNode; click NetworkTrafficSignatureAnalysis href "/technique/d3f:NetworkTrafficSignatureAnalysis";