External user added a link to a Microsoft Teams chat
Synopsis
Activation Period
14 Days
Training Period
30 Days
Test Period
N/A (single event)
Deduplication Period
1 Day
Required Data
Office 365 Audit
Detection Modules
Identity Threat Module, SaaS Threat Detection
Detector Tags
Microsoft Teams
ATT&CK Tactic
Initial Access (TA0001)
ATT&CK Technique
Phishing (T1566)
Severity
Informational
Description
An external user added a link to a Microsoft Teams chat.
Attacker's Goals
Attackers may leverage Microsoft Teams to conduct phishing attacks by exploiting trusted communication channels with users inside the organization.
Investigative actions
Confirm that the external tenant and user are authorized to share links or files with users in the organization.
Verify the content of the conversation and validate that there is no phishing attempt being made.
Inspect links and URLs that have been sent in the conversation.
Evaluate the external domain reputation.
Review past communication from the external user.
Follow further actions done by the account.
Variations
Was this helpful?
