Analytics Alerts

Browse the Cortex analytics alert reference.

Severity
Detection module
Data source

1 alert match the current filters.

Download CSV Show ATT&CK heatmap
  • User exported multiple messages in Microsoft Teams via Graph API Informational Identity Threat Module, SaaS Threat Detection 3 variations

    A user exported multiple messages in Microsoft Teams via Graph API.

    Activation:
    14 Days
    Training:
    30 Days
    Test:
    1 Hour
    Deduplication:
    1 Day
    ATT&CK tactics: Collection (TA0009)
    ATT&CK techniques: Data from Information Repositories: Messaging Applications (T1213.005)
    Required data: Office 365 Audit
    Detector tags: Microsoft Teams
    Attacker's goals: Attackers may leverage messages extraction from Microsoft Teams to collect sensitive data.
    Investigative actions: Confirm that the exported messages were extracted from a certified and trusted entity. Determine if it is within the user's role to extract messages from Microsoft Teams. Follow further actions done by the account and validate that the exported conversations were not sent to an untrusted entity.

    Variations

    User exported multiple chats in Microsoft Teams via Graph API

    Low overridden

    A user exported multiple messages in Microsoft Teams via Graph API. overridden

    User exported multiple messages in Microsoft Teams via Graph API by a privileged user for the first time

    Low overridden

    A user exported multiple messages in Microsoft Teams via Graph API. overridden

    User exported multiple messages in Microsoft Teams via Graph API from a first seen ASN

    Low overridden

    A user exported multiple messages in Microsoft Teams via Graph API. overridden