Skip to content
AI-020 Accounts & Identity

What is a session cookie?


id: "AI-020" title: "What is a session cookie?" series: "Accounts and Identity" content_type: "video-script" status: "draft" owner: "IF Digital"


What is a session cookie?

Script

You log into a website once.

Then you move between pages without entering the password again.

That usually works because the website has created a session.

A session cookie is a small piece of data stored by the browser to help the website recognise that the user has already authenticated.

It is not normally the password itself.

Instead, it acts like a temporary reference to an authenticated session held by the service.

When the browser sends the cookie back, the website may allow access without asking for the password again.

That matters to investigators because possession of a valid session cookie can sometimes allow access to an account even where the password is unknown.

A person may simply reopen a browser and continue an existing session.

Malware or an attacker may steal session data from a device and use it elsewhere.

A shared device may remain logged in long after the original user has walked away.

The exact behaviour depends on the service.

Some cookies expire when the browser closes.

Others remain valid for days, weeks or longer.

Some are tied to a particular device or security context.

Others can be reused more easily.

Look at what the evidence actually shows.

Was a live session present on the device?

Did the browser contain cookies linked to the account?

Was the account accessible without entering credentials?

Did the provider record a new login, or only continued activity within an existing session?

Be careful with language.

A session cookie can support the conclusion that the device had access to the account.

It does not automatically prove who originally authenticated, who later used the session, or whether the password was known.

A session cookie is evidence of an authenticated session.

It can explain how account access continued without a fresh login.

Treat it as part of the access story, not as a shortcut to identifying the user.


Keep moving

Where this question leads

These links explain why the next page may matter, rather than presenting an undifferentiated list.