Analytics Alerts

Browse the Cortex analytics alert reference.

Severity
Detection module
Data source
  • A Microsoft Teams bot was added to a team Informational Identity Threat Module, SaaS Threat Detection

    A user added a bot to a team in Microsoft Teams.

    Activation:
    14 Days
    Training:
    30 Days
    Test:
    N/A (single event)
    Deduplication:
    1 Day
    ATT&CK tactics: Persistence (TA0003)
    ATT&CK techniques: Cloud Application Integration (T1671)
    Required data: Office 365 Audit
    Detector tags: Microsoft Teams
    Attacker's goals: Attackers may leverage Teams bots to maintain persistent access to compromised Teams accounts.
    Investigative actions: Confirm that the bot was created by a certified and trusted entity. Evaluate the permissions requested by the bot to determine if they are excessive or unusual. Determine if it is within the user's role to add bots to teams. Follow further actions done by the account.