For the complete documentation index, see llms.txt. This page is also available as Markdown.

New Teams application published to the organization catalog

Synopsis

Field
Value

Activation Period

14 Days

Training Period

30 Days

Test Period

N/A (single event)

Deduplication Period

1 Day

Required Data

Office 365 Audit

Detection Modules

Identity Threat Module, SaaS Threat Detection

Detector Tags

Microsoft Teams

ATT&CK Tactic

Persistence (TA0003)

ATT&CK Technique

Account Manipulation (T1098)

Severity

Informational

Description

A new Teams application was published to the organization catalog.

Attacker's Goals

Attackers may leverage Teams applications to maintain persistent access to compromised Teams accounts.

Investigative actions

  • Confirm that the application was created by a certified and trusted entity.

  • Evaluate the permissions requested by the application to determine if they are excessive or unusual.

  • Determine if it is within the user's role to publish this type of application.

  • Correlate the alert with the sign-in event to get additional information on the identity performing the action.

  • Follow further actions done by the account.

Variations

A Microsoft Teams application was published to the organization catalog by an unusual user

Synopsis

Field
Value

ATT&CK Tactic

Persistence (TA0003)

ATT&CK Technique

Account Manipulation (T1098)

Severity

Low

Description

A new Teams application was published to the organization catalog.

Attacker's Goals

Attackers may leverage Teams applications to maintain persistent access to compromised Teams accounts.

Investigative actions

  • Confirm that the application was created by a certified and trusted entity.

  • Evaluate the permissions requested by the application to determine if they are excessive or unusual.

  • Determine if it is within the user's role to publish this type of application.

  • Correlate the alert with the sign-in event to get additional information on the identity performing the action.

  • Follow further actions done by the account.

Was this helpful?