A seasoned infrastructure professional and a web developer walk into a red team engagement. The point-of-contact says “Hey, we have an extremely mature security model, and we inspect all the traffic.” So what does our red team do? They write a tool to exfiltrate data, encoded, obfuscated, and hidden in plain sight in HTTP traffic. And when you write a tool that exfils data via cookies, what do you call it? We called it Cookie Monster, and this session is all about it, how it’s built and functions, its usage of other auth methods for hiding payloads, its relatively young command and control functionality, and what the development roadmap looks like for the future.