Analytics Alerts
Browse the Cortex analytics alert reference.
1 alert match the current filters. tactic: TA0009 ✕ technique: T1213 ✕
Download CSV Show ATT&CK heatmapUser exported multiple messages in Microsoft Teams via Graph API Informational Identity Threat Module, SaaS Threat Detection 3 variations
A user exported multiple messages in Microsoft Teams via Graph API.
- Activation:
- 14 Days
- Training:
- 30 Days
- Test:
- 1 Hour
- Deduplication:
- 1 Day
ATT&CK tactics: Collection (TA0009)ATT&CK techniques: Data from Information Repositories: Messaging Applications (T1213.005)Required data: Office 365 AuditDetector tags: Microsoft TeamsAttacker's goals: Attackers may leverage messages extraction from Microsoft Teams to collect sensitive data.Investigative actions: Confirm that the exported messages were extracted from a certified and trusted entity. Determine if it is within the user's role to extract messages from Microsoft Teams. Follow further actions done by the account and validate that the exported conversations were not sent to an untrusted entity.Variations
User exported multiple chats in Microsoft Teams via Graph API
Low overridden
A user exported multiple messages in Microsoft Teams via Graph API. overridden
User exported multiple messages in Microsoft Teams via Graph API by a privileged user for the first time
Low overridden
A user exported multiple messages in Microsoft Teams via Graph API. overridden
User exported multiple messages in Microsoft Teams via Graph API from a first seen ASN
Low overridden
A user exported multiple messages in Microsoft Teams via Graph API. overridden