For the complete documentation index, see llms.txt. This page is also available as Markdown.

External user added a link to a Microsoft Teams chat

Synopsis

Field
Value

Activation Period

14 Days

Training Period

30 Days

Test Period

N/A (single event)

Deduplication Period

1 Day

Required Data

Office 365 Audit

Detection Modules

Identity Threat Module, SaaS Threat Detection

Detector Tags

Microsoft Teams

ATT&CK Tactic

Initial Access (TA0001)

ATT&CK Technique

Phishing (T1566)

Severity

Informational

Description

An external user added a link to a Microsoft Teams chat.

Attacker's Goals

Attackers may leverage Microsoft Teams to conduct phishing attacks by exploiting trusted communication channels with users inside the organization.

Investigative actions

  • Confirm that the external tenant and user are authorized to share links or files with users in the organization.

  • Verify the content of the conversation and validate that there is no phishing attempt being made.

  • Inspect links and URLs that have been sent in the conversation.

  • Evaluate the external domain reputation.

  • Review past communication from the external user.

  • Follow further actions done by the account.

Variations

Was this helpful?