What is a session cookie?¶
A session cookie is a small piece of browser-held data that helps a website recognise an existing logged-in session.
It is usually not the account password. It is more like a continuing reference to authenticated access that has already been granted.
That matters because an account can keep being used without another password entry.
What happens after login?¶
A simplified sequence looks like this:
This is why a browser can remain signed in for days or weeks.
What can be useful to an investigator?¶
Depending on the browser and service, useful details may include:
- cookie or token name;
- domain;
- storage location;
- creation time;
- expiry time;
- session identifier;
- account association;
- browser profile; and
- surrounding browsing history.
A recovered cookie may help explain why account activity happened without a fresh login.
A cookie can outlive the login event¶
Suppose the account was authenticated on Monday.
The browser may still be using the same session on Friday.
If disputed activity happens on Friday, you may find no fresh password event at all.
That does not mean the Friday activity is unexplained. It means you need to follow the continuing session.
What is a login session? explains that wider relationship.
Possession of a cookie is not the same as identity¶
A shared computer may retain a live session.
A device may be stolen or remotely controlled.
Session material may sometimes be copied and reused elsewhere.
So the presence of a session cookie can show that the browser held authenticated session material, but you still need to work out who controlled the device or session when the relevant activity occurred.
Do not activate a live session casually¶
Opening an existing session may alter account state, trigger security events, synchronise data or notify the provider or user.
If live access is genuinely needed, treat that as a deliberate investigative action rather than simply clicking through.
The practical point is: a session cookie can explain continued account access without another password event. Use it to connect browser activity to a session, then attribute the use of that session separately.