ExtraHop named a leader in the Gartner® Magic Quadrant™ for Network Detection and Response

Search
  • Platformchevron right
  • Solutionschevron right
  • Modern NDRchevron right
  • Resourceschevron right
  • Companychevron right

DETECTION OVERVIEW

Session Hijacking Attempt

Risk Factors

An unauthenticated attacker must first steal a session token by compromising the device through methods such as malware infection or machine-in-the-middle (MITM) attacks. By manually crafting HTTP requests, the attacker can reuse the stolen token to authenticate as the victim.

Category

Exploitation

Decryptions

TLS Decryption
Detection diagram
Next in Exploitation: Shellshock DHCP Exploit Attempt

Background

The HTTP protocol lacks a built-in mechanism to maintain user authentication across multiple web requests. Web applications issue unique authentication tokens or session cookies to maintain active sessions without repeated login prompts. Session hijacking occurs when an attacker steals one of these active tokens by compromising a device and reuses the token from their external device, which enables the attacker to identify as the previously authenticated user.

The new connection generates network traffic that does not match previously identified client characteristics, such as TLS versions or supported cipher suites. Changes in client characteristics indicate the token was replayed from a new device. If successful, the attacker gains unauthorized access to perform malicious actions as the legitimate user.

Mitigation Options

Invalidate user sessions on the target application, which disables the token.

MITRE ATT&CK ID

Associated content

Announcing The Forrester Wave™: Network Analysis And Visibility Solutions, Q4 2025

Network analysis and visibility solutions remain underrepresented in enterprises. Find out why in this preview of a new Wave report.

Blog Post

ExtraHop® Named a Leader in First-Ever Gartner® Magic Quadrant™ for Network Detection and Response — ExtraHop

ExtraHop® Named a Leader in First-Ever Gartner® Magic Quadrant™ for Network Detection and Response

News

Detections

Visit this resource for more information.

Documentation

Decryption

Learn how ExtraHop decryption works.

Documentation

The 2025 ExtraHop Global Threat Landscape Report: The Alarming Reality of Threat Actor Dwell Time and Deeper Network Access — ExtraHop

This analysis exposes the critical link between an organization's lack of internal visibility and the escalating cost of compromise, demanding an urgent re-evaluation of how core business assets are protected.

Blog Post

ExtraHop RevealX MITRE ATT&CK Coverage 2024 — ExtraHop

Learn why you need to be wary of the claims certain network detection and response providers make about their coverage against the MITRE ATT&CK framework.

Blog Post

MITRE ATT&CK - Network Detection & Response with RevealX — ExtraHop

Learn how NDR from RevealX helps security teams detect and investigate more adversary TTPs in the MITRE ATT&CK framework than rule-based tools.

Report
Periodic Table of Use Cases

What else can RevealX do for you?