
Not Just Cookies: Modern Session Abuse | SO-CON 26
Source: YouTube · SpecterOps · published Jun 4, 2026 · 50:28
This talk introduces "Modern Session Abuse," focusing on how red team operators can pivot laterally to high-value targets located behind web applications with Single Sign-On (SSO) 0:12.
Key Takeaways:
• Presented by SpecterOps consultants Andrew and Intero, the session covers practical techniques for moving laterally through web applications as a compromised user 0:00.
• Red teams frequently encounter high-value targets that are protected by web apps utilizing SSO, requiring specific pivoting strategies 0:21.
• The presentation is designed to demonstrate both offensive session abuse techniques and corresponding defensive detection and prevention strategies 0:32.
The talk sets the stage for understanding session abuse in modern environments by bridging the gap between offensive tactics and defensive mitigations 0:38.
Sources:
Generate CPE Credits
Generate a professional CPE document from this video's transcript.
Estimated credit: 1 CPE hours
Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.
Topic: Cybersecurity. Commonly maps to: Security and Risk Management, Security Operations. Exact CISSP domains are assigned during generation.
Free account. One generation at a time, with a daily limit.
CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.
Transcript Preview
First 800 characters of the transcript
Thanks everyone for coming. I'm Andrew. That's my partner intero. We're both consultants here at Spectre Ops and welcome to not just cookies but modern session abuse. I'll try not to mess up these slides. Uh but essentially if you're interested about this talk the quick down and dirty is as operators oftentimes during red team engagements we're asked to pivot to a highv value target. Those are often behind some sort of web application and sometimes those web applications have single sign enabled. So we're going to demonstrate ways as an operator to move laterally to those targets. um specifically to that web application as the user, but also highlight some detection and prevention opportunities as a defender. Uh the agenda for today is a little bit of background information about how Chrom…