External user started a Microsoft Teams conversation
Synopsis
Activation Period
14 Days
Training Period
30 Days
Test Period
1 Hour
Deduplication Period
1 Day
Required Data
Office 365 Audit
Detection Modules
Identity Threat Module, SaaS Threat Detection
Detector Tags
Microsoft Teams
ATT&CK Tactic
Initial Access (TA0001)
ATT&CK Technique
Phishing (T1566)
Severity
Informational
Description
An external user started a Microsoft Teams conversation with users in the organization.
Attacker's Goals
Attackers may leverage Microsoft Teams to conduct phishing attacks by exploiting trusted communication channels with users inside the organization.
Investigative actions
Confirm that the tenant and user are authorized to start a conversation with users in the organization.
Verify the content of the conversation and validate that there is no phishing attempt being made.
Inspect links and URLs that might have been sent in the conversation.
Check external domain reputation.
Review past communication from the external user.
Follow further actions done by the account.
Variations
Was this helpful?
