Analytics Alerts

Browse the Cortex analytics alert reference.

Severity
Detection module
Data source

1 alert match the current filters. tactic: TA0001 ✕

Download CSV Show ATT&CK heatmap
  • External user added a link to a Microsoft Teams chat Informational Identity Threat Module, SaaS Threat Detection 1 variation

    An external user added a link to a Microsoft Teams chat.

    Activation:
    14 Days
    Training:
    30 Days
    Test:
    N/A (single event)
    Deduplication:
    1 Day
    ATT&CK tactics: Initial Access (TA0001)
    ATT&CK techniques: Phishing (T1566)
    Required data: Office 365 Audit
    Detector tags: Microsoft Teams
    Attacker's goals: Attackers may leverage Microsoft Teams to conduct phishing attacks by exploiting trusted communication channels with users inside the organization.
    Investigative actions: Confirm that the external tenant and user are authorized to share links or files with users in the organization. Verify the content of the conversation and validate that there is no phishing attempt being made. Inspect links and URLs that have been sent in the conversation. Evaluate the external domain reputation. Review past communication from the external user. Follow further actions done by the account.

    Variations

    An external user sent a link via Microsoft Teams with suspicious parameters

    Low overridden

    An external user sent a link with suspicious parameters in a Microsoft Teams conversation. overridden