Analytics Alerts

Browse the Cortex analytics alert reference.

Severity
Detection module
Data source

1 alert match the current filters. technique: T1555 ✕

Download CSV Show ATT&CK heatmap
  • Uncommon access to Microsoft Teams cookies files Informational Identity Analytics 1 variation

    Sensitive Microsoft Teams cookies files were accessed.

    Activation:
    14 Days
    Training:
    30 Days
    Test:
    10 Minutes
    Deduplication:
    1 Day
    ATT&CK tactics: Credential Access (TA0006)
    ATT&CK techniques: Credentials from Password Stores (T1555) Steal Application Access Token (T1528)
    Required data: XDR Agent with eXtended Threat Hunting (XTH)
    Detector tags: Microsoft Teams
    Attacker's goals: Attacker may access credentials files and steal application access tokens to gain remote access.
    Investigative actions: Investigate the actor process to determine if it was used for legitimate purposes or malicious activity. Review the host for any additional unusual activity. Investigate the Graph API calls followed by the user that might be related.

    Variations

    Suspicious uncommon access to Microsoft Teams cookies files

    Low overridden

    Sensitive Microsoft Teams cookies files were accessed by a suspicious process. overridden