2026 Critical Enterprise Intrusion Chain Detection: Pass-the-Cookie Cross-Service Session Reuse

Detects anomalous authentication patterns where a user account accesses a large number of distinct SaaS/SSO resources within a short time frame from devices or IP addresses not previously associated with the user's historical baseline. This behavior is indicative of a stolen session cookie being replayed by an adversary to perform rapid lateral movement across the victim's cloud footprint.