For the complete documentation index, see llms.txt. This page is also available as Markdown.

A Microsoft Teams bot was added to a team

Synopsis

Field
Value

Activation Period

14 Days

Training Period

30 Days

Test Period

N/A (single event)

Deduplication Period

1 Day

Required Data

Office 365 Audit

Detection Modules

Identity Threat Module, SaaS Threat Detection

Detector Tags

Microsoft Teams

ATT&CK Tactic

Persistence (TA0003)

ATT&CK Technique

Cloud Application Integration (T1671)

Severity

Informational

Description

A user added a bot to a team in Microsoft Teams.

Attacker's Goals

Attackers may leverage Teams bots to maintain persistent access to compromised Teams accounts.

Investigative actions

  • Confirm that the bot was created by a certified and trusted entity.

  • Evaluate the permissions requested by the bot to determine if they are excessive or unusual.

  • Determine if it is within the user's role to add bots to teams.

  • Follow further actions done by the account.

Was this helpful?