Category: Security · View source ↗
Security
Session Token Theft Response
An account shows malicious activity even though MFA passed and the password looks fine — a stolen session cookie or token is in play, so revoke sessions and tokens, not just the password.
Connectors: none — works with Thread out of the box
Role: Security & Compliance Owner, Technician
Outcome: Faster Resolution & Response, Risk & Compliance
When to use: Malicious or anomalous activity on an account where sign-in logs show MFA succeeded and no password change explains it; a user’s session appears active from an unfamiliar IP/device while the user is elsewhere; or post-phishing where the lure harvested a session (adversary-in-the-middle / token-replay), not just credentials.
Run it: on one ticket (a suspected stolen-session case).
Related topics
Lost or Stolen Device ResponseBusiness Email Compromise RecoveryWatchGuard Firewall AlertsWas this page helpful?
⌘I