Return of the Cookie Monster: Chromium DevTools Protocol for Session Theft
SpecterOps research explores using the Chrome DevTools Protocol (CDP) to perform post-exploitation activities, including browser enumeration, cookie theft, and browser takeover. While traditional cookie protections have made session theft harder, CDP offers a new avenue for adversaries to exploit authenticated browser sessions. This deep dive provides insights into advanced browser-based attack techniques.