The goodsru куки · session token

Session cookie

The token that proves a browser is already logged in, copied straight out of a victim's browser by an infostealer. Replayed elsewhere it opens the account without the password and without a second factor.

Why it matters to you

A password reset does not invalidate a stolen session; only revoking the session does. If a device turns up in a log, the response is to kill the sessions, not just rotate the credential.

Where we meet it

Cookies are the part of a log with the shortest shelf life and the highest value, which is why the resale market moves them fastest. Reading a batch on the day it lands is what decides whether the warning is useful.

Where this term stops being vocabulary

Sherlog is where you watch it happen to you

Knowing the word is the cheap half. The platform is the half where the term arrives attached to your domain, with a timestamp and the source it came from.