Analytics Alerts
Browse the Cortex analytics alert reference.
1 alert match the current filters.
Download CSV Show ATT&CK heatmapMicrosoft Teams messages were exported from conversation Informational Identity Threat Module, SaaS Threat Detection 1 variation
Microsoft Teams messages were exported from conversation.
- Activation:
- 14 Days
- Training:
- 30 Days
- Test:
- N/A (single event)
- Deduplication:
- 1 Day
ATT&CK tactics: Collection (TA0009)ATT&CK techniques: Data from Information Repositories: Messaging Applications (T1213.005)Required data: Office 365 AuditDetector tags: Microsoft TeamsAttacker's goals: Attackers may leverage message extraction from Microsoft Teams to obtain valuable information.Investigative actions: Confirm that the exported messages were extracted from a certified and trusted entity. Determine if it is within the user's role to extract messages from Microsoft Teams. Follow further actions done by the account and validate that the exported conversations were not sent to an untrusted entity.Variations
Microsoft Teams messages were exported from conversation by a privileged user for the first time
Low overridden
Microsoft Teams messages were exported from conversation. overridden