For the complete documentation index, see llms.txt. This page is also available as Markdown.

A Microsoft Teams application was installed

Synopsis

Field
Value

Activation Period

14 Days

Training Period

30 Days

Test Period

N/A (single event)

Deduplication Period

1 Day

Required Data

Office 365 Audit

Detection Modules

Identity Threat Module, SaaS Threat Detection

Detector Tags

Microsoft Teams

ATT&CK Tactic

Persistence (TA0003)

ATT&CK Technique

Cloud Application Integration (T1671)

Severity

Informational

Description

A Microsoft Teams application was installed.

Attacker's Goals

Attackers may leverage Teams applications to maintain persistent access to compromised Teams accounts.

Investigative actions

  • Confirm that the application was created by a certified and trusted entity.

  • Evaluate the permissions requested by the application to determine if they are excessive or unusual.

  • Determine if it is within the user's role to install this type of application.

  • Correlate the alert with the sign-in event to get additional information on the identity performing the action.

  • Follow further actions done by the account.

Variations

A Microsoft Teams application was installed with special parameters

Synopsis

Field
Value

ATT&CK Tactic

Persistence (TA0003)

ATT&CK Technique

Cloud Application Integration (T1671)

Severity

Low

Description

A Microsoft Teams application was installed.

Attacker's Goals

Attackers may leverage Teams applications to maintain persistent access to compromised Teams accounts.

Investigative actions

  • Confirm that the application was created by a certified and trusted entity.

  • Evaluate the permissions requested by the application to determine if they are excessive or unusual.

  • Determine if it is within the user's role to install this type of application.

  • Correlate the alert with the sign-in event to get additional information on the identity performing the action.

  • Follow further actions done by the account.

Was this helpful?