Insider Threat Matrix™Insider Threat Matrix™
  • ID: PR047.004
  • Created: 22nd July 2026
  • Updated: 22nd July 2026
  • Platforms: LinuxWindows
  • MITRE ATT&CK®: T1563T1563.001T1563.002
  • Contributor: The ITM Team

Remote Session Hijacking

The subject takes control of an existing authenticated remote service session to operate an additional organizational system under the identity and access context of the session owner. The subject may hijack an active or disconnected RDP session, reuse an SSH agent or socket, or otherwise attach to a pre-existing remote session without completing a new authentication process.