On the internal pentest fintech company, I captured the manager’s session through a stolen session cookie - Use Alternate Authentication Material: Web Session Cookies (T1550.004, Lateral Movement) Twelve minutes later, the session was killed. Not timeout, not logout, not rotation of the token -...