← Inspection rules

SEC-003 / v1.2.0 / 2026-10-02

Inspect endpoints and session revocation

Editorial inspection guidance. Start with read-only permissions; fixes, credential revocation, and production changes follow the owner’s authorization.

Applicability

Environments where endpoints or support files can expose authenticated sessions.

Where to look first

  • Endpoint management and SSO session policies
  • HAR/support attachments and logout handlers

Inspection steps

  1. Verify sanitization of cookies, Authorization headers, and personal data before sending HAR files; never output values.
  2. Inspect revocation, reauthentication, and administrator-session limits; verify old sessions cannot continue acting.

Remediation direction

  • Strengthen managed endpoints and session controls; revoke suspected sessions within granted authority.

Evidence required for completion

  • Record rejection of synthetic revoked sessions and attachment sanitization checks.

Limits and unverified scope

  • A repository cannot establish endpoint health. Cookie flags alone do not establish resistance to endpoint malware.