A Microsoft Teams bot was added to a team
Synopsis
Activation Period
14 Days
Training Period
30 Days
Test Period
N/A (single event)
Deduplication Period
1 Day
Required Data
Office 365 Audit
Detection Modules
Identity Threat Module, SaaS Threat Detection
Detector Tags
Microsoft Teams
ATT&CK Tactic
Persistence (TA0003)
ATT&CK Technique
Cloud Application Integration (T1671)
Severity
Informational
Description
A user added a bot to a team in Microsoft Teams.
Attacker's Goals
Attackers may leverage Teams bots to maintain persistent access to compromised Teams accounts.
Investigative actions
Confirm that the bot was created by a certified and trusted entity.
Evaluate the permissions requested by the bot to determine if they are excessive or unusual.
Determine if it is within the user's role to add bots to teams.
Follow further actions done by the account.
Was this helpful?
