Compliance Node Overview
MITRE ATT&CK T1539 covers adversary theft of web session cookies to bypass MFA and impersonate authenticated users. Storm-0558 (Microsoft, 2023) and SCATTERED SPIDER (Okta, 2023-2024) campaigns leveraged stolen session cookies extensively. Modern infostealers (RedLine, Vidar, Lumma, Stealc) harvest browser cookies as the primary credential exfiltration vector. Compliance: NIST 800-53 IA-5, AC-12, SC-8, ISO 27001 A.5.17, A.8.5, GDPR Article 32, PCI DSS Req 8.
Pillar: Cybersecurity · Authority: MITRE Corporation · Version: 1.0.0 · Last updated:
Primary source: https://attack.mitre.org/techniques/T1539/
SHA-256 integrity: 83545937ffa86d51f2d9e64432772c7d0c5b0d1ab66a89d7fb21bcd77dc98bf6
Primary Citations — 7 traced to source
- MITRE ATT&CK Technique T1539: Steal Web Session Cookie (https://attack.mitre.org/techniques/T1539/)
- NIST SP 800-63B: Digital Identity Guidelines
+ 5 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access
⚠ Important: Human Verification Required
Bidda compliance nodes are reference intelligence, not legal advice. Every node must be reviewed by a qualified compliance professional or legal counsel before implementation in any enterprise workflow, regulated system, or compliance programme. See bidda.com/disclaimer for full terms.