Microsoft Defender XDR
Incidents and response

Session Cookie Theft Alert

In brief

The article’s date was updated, wording was refined, an investigation-steps introduction was added, and references to Advanced hunting and business email compromise were made clearer.

What Defender admins need to know

Administrators have clearer guidance and link context when investigating session cookie theft alerts; no action is required.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

Applies to:

  • Microsoft Defender XDR

This article contains information about alert grading for Session Cookie theft alerts in Microsoft Defender XDR:Defender:

  • Stolen session cookie was used

  • Authentication request from AiTM-related phishing page The results of using this playbook are:

  • You have identified the alerts associated with AiTM as malicious (TP) or benign (FP) activities.

  • If the alerts are identified as malicious, you've taken the necessary action to remediate the attack.

Investigation steps for session cookie theft alerts

Perform the following investigation steps for session cookie theft alerts:

  1. Investigate whether the affected user has triggered any other security alerts.

    • Focus on alerts that are based on geo-location anomalies for sign ins [AadSignInEventsBeta or IdentityLogonEvents].

Advanced hunting queries

Advanced hunting overview is a query-based threat hunting tool that lets you inspect events in your network and locate threat indicators.

Before running these queries, ensure you have access to the following tables:

For more background on AiTM phishing attacks and session cookie theft, see the following resource: