Analytics BIOC Informational

A Microsoft Teams application was installed

A Microsoft Teams application was installed.

Module:
Identity Threat Detection (ITDR), SaaS Threat Detection
Licensed by:
Identity Threat Detection (ITDR)
Data source:
Office 365 Audit
ATT&CK tactics: Persistence (TA0003)
ATT&CK techniques: Cloud Application Integration (T1671)
Detector tags: Microsoft Teams
Attacker's goals:

Attackers may leverage Teams applications to maintain persistent access to compromised Teams accounts.

Investigative actions:

Confirm that the application was created by a certified and trusted entity. Evaluate the permissions requested by the application to determine if they are excessive or unusual. Determine if it is within the user's role to install this type of application. Correlate the alert with the sign-in event to get additional information on the identity performing the action. Follow further actions done by the account.

Test period:
N/A (single event)
Deduplication:
1 Day
1 variation:
  • A Microsoft Teams application was installed with special parameters Low (parent: Informational)