Analytics Alerts
Browse the Cortex analytics alert reference.
1 alert match the current filters. tactic: TA0001 ✕ technique: T1566 ✕
Download CSV Show ATT&CK heatmapExternal user added a link to a Microsoft Teams chat Informational Identity Threat Module, SaaS Threat Detection 1 variation
An external user added a link to a Microsoft Teams chat.
- Activation:
- 14 Days
- Training:
- 30 Days
- Test:
- N/A (single event)
- Deduplication:
- 1 Day
ATT&CK tactics: Initial Access (TA0001)ATT&CK techniques: Phishing (T1566)Required data: Office 365 AuditDetector tags: Microsoft TeamsAttacker's goals: Attackers may leverage Microsoft Teams to conduct phishing attacks by exploiting trusted communication channels with users inside the organization.Investigative actions: Confirm that the external tenant and user are authorized to share links or files with users in the organization. Verify the content of the conversation and validate that there is no phishing attempt being made. Inspect links and URLs that have been sent in the conversation. Evaluate the external domain reputation. Review past communication from the external user. Follow further actions done by the account.Variations
An external user sent a link via Microsoft Teams with suspicious parameters
Low overridden
An external user sent a link with suspicious parameters in a Microsoft Teams conversation. overridden