Uncommon access to Microsoft Teams cookies files
Synopsis
Activation Period
14 Days
Training Period
30 Days
Test Period
10 Minutes
Deduplication Period
1 Day
Required Data
XDR Agent with eXtended Threat Hunting (XTH)
Detection Modules
Identity Analytics
Detector Tags
Microsoft Teams
ATT&CK Tactic
Credential Access (TA0006)
ATT&CK Technique
Credentials from Password Stores (T1555), Steal Application Access Token (T1528)
Severity
Informational
Description
Sensitive Microsoft Teams cookies files were accessed.
Attacker's Goals
Attacker may access credentials files and steal application access tokens to gain remote access.
Investigative actions
Investigate the actor process to determine if it was used for legitimate purposes or malicious activity.
Review the host for any additional unusual activity.
Investigate the Graph API calls followed by the user that might be related.
Variations
Was this helpful?
