Suspicious AiTM Session Cookie Exfiltration to log_cookie Endpoint

PremiumReviewedSigma · High · v1
Category
proxy
Author
HuntRule
Published
2026-09-15
Updated
2026-09-15

ATT&CK techniques

Initial Access → Cred Access
  1. Recon

  2. Resource Dev

  3. Execution

  4. Discovery

  5. Lateral Movement

  6. Collection

  7. C2

  8. Exfiltration

  9. Impact

What it detects

This rule detects web requests to a log_cookie collection endpoint carrying stolen session identifiers such as idx, JSESSIONID, and sid, the harvesting path used by the AiTM phishing kit. The reverse proxy captures live authenticated cookies from M365 and Okta victims and ships them to attacker infrastructure for session hijacking. Traffic to this endpoint with session token parameters indicates successful token theft.

Related detections9 linkedT1539 — drag to rearrange
Suspicious Entra Sign-In to OfficeHome with axios User Agent
Suspicious 1Phish Kit Cookies and Telemetry Beacon
Possible SES Sending Configuration Enumeration via CloudTrail
Suspicious AWS Role Assumption via Cognito Web Identity
Malicious Madgicx Plus Extension C2 Domain Resolution
Suspicious Google Cloud Function Create or Update Triggering Build
Malicious RemusStealer Credential Exfiltration to pics TLD C2
Possible Citrix Bleed Session Token Leak via OpenID Configuration Endpoint (CVE-2023-4966) (via webserver)
Uncommon Browser Launched with Remote Debugging Port for Cookie Theft (via process_creation)
Suspicious AiTM Session Cookie Exfiltration to log_cookie Endpoint
Pivot detection · T1539 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.