Session Integrity
Test whether your applications are able to stop, detect, or notice a replayed session. Use the tool to run 9 scenarios across escalating attack tiers and different user populations.

Internal
Partner
Customer
T1Cookie replayCookie replay
T2Session hijackSession hijack
T3IMPaaSIdentity impersonation
Results:
L0 No risk signals
L1 Indirect risk signals
L2 Session risk alert
L3 Threat alert
L4 Prevented & no alert
L5 Prevented & alert
Before you begin
Session integrity assessment
We have prepared for you a session replay harness. It simulates three real-world attack scenarios — a cookie replay, a stolen session replayed from an attacker's device, and, at the top tier, from a device made to look like yours.
It allows you to see whether an app stops them. All results stay in this browser tab only.
Prerequisites
- /An active account (strong MFA recommended)
- /Two different machines (target and attacker)
- /Read access to your detection telemetry (IdP, EDR, SIEM, app logs)
- /Relock session replay harness (available on GitHub)